跳转到帖子

MOVEit SQL Injection vulnerability

recommended_posts

发布于
  • Members

MOVEit SQL Injection vulnerability

Disclosed
05/31/2023
Created
06/22/2023

Description

This module exploits an SQL injection vulnerability in the MOVEit Transfer web application that allows an unauthenticated attacker to gain access to MOVEit Transfer’s database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker can leverage an information leak be able to upload a .NET deserialization payload.

Author(s)

  • sfewer-r7
  • rbowes-r7
  • bwatters-r7

Platform

Windows

Architectures

cmd

Development

  • Source Code
  • History
  • 查看数 699
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…