
a standalone C-based SQL Injection exploit targeting the CVE‑2025‑6907 vulnerability in the CODE_PROJECT service.
File: exploit.c
Author: Byte Reaper
Target Service: CODE_PROJECT
Type: SQL Injection
This is a standalone C-based SQL Injection exploit targeting the CVE‑2025‑6907 vulnerability in the CODE_PROJECT service.
It combines multiple advanced techniques:
/proc/self/maps)-u / --url, -i / --input)-r / --response)-c / --check)-v / --verbose):
curl logs-h / --help) with full argument explanationsgcc, makelibcurl development headersargparse.h (C argument‑parser header)gcc exploit.c argparse.c -o exploit -lcurl 🚀 Usage
./exploit [options] Arguments Short Long Description -h --help Show detailed help and exit. -u --url Base URL (partial). Appends payloads to book_car.php?fname= by default. -i --input Treat provided URL as full (including query). -r --response Print HTTP response bodies for each payload attempt. -c --check Perform environment checks (files, folders, Apache processes). -v --verbose Enable verbose logs, payload address mapping, and memory map dump.
Examples Basic scan
./exploit -u http://127.0.0.1 Show server responses
./exploit -u http://127.0.0.1 -r Full‑URI mode
./exploit -u "http://127.0.0.1 Environment & Apache check sudo ./exploit -c Verbose with memory map
sudo ./exploit -i http://127.0.0.1/book_car.php?fname= -v OR sudo ./exploit -i http://127.0.0.1/folder/file.php?fname= 🧩 How It Works Startup checks
Ensures running on Linux
Requires root for some operations (memory map, directory syscalls)
Argument parsing
Uses argparse.h to handle flags and options
Environment inspection (-c)
Scans /var/www/html for known CODE_PROJECT folders
Lists and classifies important PHP files
Checks/runs Apache service
Payload injection loop
Iterates a list of SQL strings (boolean, UNION, time‑based…)
URL‑encodes and sends via libcurl
Detects SQLi via response signatures or time delays
Advanced logging (-v)
Prints each payload’s memory address and length
Dumps /proc/self/maps memory regions
⚠️ Disclaimer For authorized testing only. Do NOT use against systems you do not own or have explicit permission to test.
Use responsibly and ethically.
📜 License This work is provided “as-is” without warranty of any kind. Use at your own risk.