Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
phpipam_1.4.4 — CVE-2022-23046 phpIPAM 1.4.4 | Kitploit
Tools/GitHubGitHub/hadrian3689/phpipam_1.4.4
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubhadrian3689/phpipam_1.4.4

phpipam_1.4.4

CVE-2022-23046 phpIPAM 1.4.4

View Repository
3 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-23046 phpIPAM 1.4.4 - SQL Injection

phpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the subnet parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php. This project currently prints out database information and host version information. It can also attempt to read files and write to the server as well.

Getting Started

Executing program

  • To check if it is vulnerable.
root@kitploit:~
python3 phpipam_1.4.4.py -t http://phpipam.com/ -u username -p password
  • For test for file read
root@kitploit:~
python3 phpipam_1.4.4.py -t http://phpipam.com/ -u username -p password -f /etc/passwd
  • For test for file write
root@kitploit:~
python3 phpipam_1.4.4.py -t http://phpipam.com/ -u username -p password -w /var/www/html/cmd.php

Help

For Help Menu

root@kitploit:~
python3 phpipam_1.4.4.py -h

Acknowledgments

  • FluidAttacks

Disclaimer

All the code provided on this repository is for educational/research purposes only. Any actions and/or activities related to the material contained within this repository is solely your responsibility. The misuse of the code in this repository can result in criminal charges brought against the persons in question. Author will not be held responsible in the event any criminal charges be brought against any individuals misusing the code in this repository to break the law.

Download Tool