Junglewise Threat Intelligence

CVE-2018-25413: hayinfx AiOPMSD SQL injection in search.php

CVE-2018-25413 · Severity: high · CVSS 8.2 · Published 2026-05-30

Technologies: Hayinfx All in one pack Online Movie Streaming. Vendors: Hayinfx.

Executive brief

AiOPMSD, a PHP-based movie streaming and content management system, contains a security flaw that allows unauthorized individuals to access its underlying database. By sending specially crafted web requests, an attacker can bypass security controls to steal sensitive information such as database structures, usernames, and system version details. This could lead to a total compromise of the website's data and provide a foothold for further attacks on the hosting server.

Technical details

A SQL injection vulnerability exists in AiOPMSD Final 1.0.0 due to improper neutralization of special elements in SQL commands (CWE-89). The vulnerability is primarily exposed through the 'q' parameter in search.php, though proof-of-concept code indicates similar flaws in actor.php, director.php, country.php, and other modules. An unauthenticated remote attacker can exploit this by sending crafted GET requests containing SQL payloads. Successful exploitation allows the attacker to perform unauthorized queries, potentially leading to the extraction of sensitive database information, including user credentials and configuration details. No patch is currently known for this legacy software.

Affected products

  • hayinfx All in one pack Online Movie Streaming (AiOPMSD) 1.0.0 Final

Timeline

  • 2018-10-24: disclosed: Original exploit published on Exploit-DB
  • 2026-05-30: advisory: CVE formally published and assigned by VulnCheck

References

Related threats