Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-0944 — SQLPad - Template injection (POC exploit for SQLPad RCE [CVE-2022-0944]) | Kitploit
Tools/GitHubGitHub/flojboj/cve-2022-0944
Vulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingLearning & Education
GitHubflojboj/cve-2022-0944

CVE-2022-0944

SQLPad - Template injection (POC exploit for SQLPad RCE [CVE-2022-0944])

View Repository
5492 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-0944

SQLPad - Template injection

This is a blind vulnerability, meaning that the output is directly returned in the response.

Exploit

Use the script with the following command:
python3 exploit.py --url http://localhost:13000 --command 'ls -la > /tmp/test' --username admin --password password

Output

[*] Login was successfull
[*] Exploited!

Testing environment

Using docker:

  • Start the docker container - sudo docker run -p 13000:3000 -d --env SQLPAD_ADMIN=admin --env SQLPAD_ADMIN_PASSWORD=password --name vulnerable-sqlpad sqlpad/sqlpad:6.10.0
  • Connect to the docker container - sudo docker exec -it vulnerable-sqlpad /bin/bash

To access the web interface, use URL http://localhost:13000 with credentials admin:password.

Affected versions

<= 6.10.0

Source

https://huntr.com/bounties/46630727-d923-4444-a421-537ecd63e7fb

Disclaimer

Use only for educational purposes or CTF challenges.

Download Tool