A template injection vulnerability exists in the connection test endpoint of sqlpad/sqlpad prior to version 6.10.1. This flaw allows an attacker to inject arbitrary template code, which is subsequently executed by the server, resulting in remote code execution (RCE).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository is a small standalone Python exploit project with four files: a misleading README, a generic SECURITY.md, requirements.txt, and the actual exploit in exploit.py. Despite the README claiming CVE-2022-0944 in Linux OverlayFS, the code is unrelated to OverlayFS and instead implements a proof-of-concept against SQLPad, specifically referencing SQLPad 6.10.0 in the usage example. The exploit is therefore best understood as a SQLPad RCE PoC mislabeled with an unrelated CVE. The main logic is entirely in exploit.py. It accepts a target base URL, attacker listener host and port, and optional credentials. If credentials are provided, it authenticates to the target using POST requests to /api/signin. It then starts a local listener using pwntools and sends a crafted POST request to /api/test-connection. The JSON body places a template expression in the name field that invokes Node.js child_process.exec via process.mainModule.require('child_process').exec(...). That command launches a Perl reverse shell which connects back to the supplied lhost:lport and executes /bin/sh interactively. Exploit capability: authenticated or unauthenticated remote code execution against a SQLPad instance, followed by an interactive reverse shell. The exploit checks success heuristically by expecting HTTP 400 with ECONNREFUSED in the response, while the real shell is handled asynchronously by the listener thread. Notable indicators and structure: exploit.py is the only meaningful code file and clear entry point; requirements.txt includes requests and pwntools dependencies needed for HTTP interaction and listener handling. No persistence, privilege escalation, lateral movement, or cleanup logic is present. This is an operational PoC with a hardcoded reverse-shell payload rather than a generalized framework module.
This repository contains an operational exploit for CVE-2022-0944, a privilege escalation vulnerability in the Linux kernel's OverlayFS subsystem, with a focus on exploiting SQLPad instances running on vulnerable kernels. The main exploit logic is implemented in 'exploit.py', which uses Python and the pwntools library. The exploit works by authenticating to a SQLPad instance (if credentials are provided), then sending a specially crafted payload to the '/api/test-connection' endpoint. This payload leverages a template injection vulnerability to execute arbitrary commands on the server, specifically a Perl reverse shell that connects back to the attacker's machine. The exploit requires the attacker to provide the target URL, their own host and port for the reverse shell, and optionally SQLPad credentials. The repository also includes a README with detailed technical background, detection, and mitigation steps for the vulnerability, as well as a requirements.txt for dependencies. No hardcoded IPs or domains are present; the exploit is designed to be used against arbitrary SQLPad instances specified by the user. The attack vector is network-based, targeting exposed SQLPad web interfaces.
This repository contains a Bash script exploit for CVE-2022-0944, a remote code execution vulnerability in SQLPad version 6.10.0. The exploit abuses unsanitized template injection in the 'host' and 'database' fields of SQLPad's MySQL connection settings, allowing arbitrary command execution via Node.js's child_process module. The script prompts the user for the target host and attacker's IP, instructs the user to set up a netcat listener, and then sends a crafted HTTP POST request to the target's /api/test-connection endpoint. If successful, the target server initiates a reverse shell connection to the attacker's machine on port 9001. The repository consists of the exploit script and a README.md file with usage instructions and vulnerability details. The exploit is operational, providing a working reverse shell payload, and targets SQLPad 6.10.0 specifically.
This repository contains a proof-of-concept exploit for CVE-2022-0944, a remote code execution vulnerability in SQLPad. The exploit is implemented in a single Python script (poc-cve-2022-0944.py) and is accompanied by a README.md with usage instructions and references. The exploit works by sending a specially crafted JSON payload to the /api/test-connection endpoint of a vulnerable SQLPad instance. The payload leverages Node.js template injection to execute arbitrary commands on the server, demonstrated by spawning a reverse shell to the attacker's machine. The attacker must provide the target URL, their own IP address, and a listening port. The exploit is operational and provides a working reverse shell if the target is vulnerable. No detection or scanning functionality is present; the script is solely for exploitation.
This repository contains a PHP exploit script (exploit.php) and a README.md. The exploit targets a Remote Code Execution (RCE) vulnerability in SQLPad (CVE-2022-0944). The PHP script takes three arguments: the root URL of the vulnerable SQLPad instance, the attacker's IP address, and the attacker's listening port. It crafts a malicious payload that leverages Node.js template injection to execute a bash reverse shell command on the target server. The payload is sent via a POST request to the /api/test-connection endpoint of SQLPad. If the exploit is successful, the attacker receives a reverse shell connection, granting remote access to the server. The README provides clear usage instructions and references. The repository is a functional, operational exploit (not just a proof of concept), and is not part of a larger framework.
This repository contains a Python exploit script (exploit.py) targeting CVE-2022-0944, a Remote Code Execution (RCE) vulnerability in SQLPad versions prior to 6.10.1. The exploit abuses the '/api/test-connection' HTTP endpoint by sending a specially crafted payload that leverages Node.js template injection to execute arbitrary commands. The payload opens a reverse shell from the target server to the attacker's machine using bash and a TCP connection. The attacker must provide the SQLPad root URL, their own IP, and a listening port. The repository consists of a README.md with usage instructions and references, and the exploit.py script, which is the main entry point and contains all exploit logic. The exploit is operational and provides a reverse shell if successful, requiring the attacker to set up a netcat listener to receive the connection.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.