Junglewise Threat Intelligence

CVE-2018-25415: AiOPMSD SQL injection in multiple PHP components

CVE-2018-25415 · Severity: high · CVSS 8.2 · Published 2026-05-30

Technologies: Hayinfx All in one pack Online Movie Streaming. Vendors: Hayinfx.

Executive brief

AiOPMSD is a PHP-based content management system used for building movie streaming and download websites. A security flaw allows unauthenticated attackers to access the underlying database, potentially exposing sensitive information such as user credentials and system configuration. This could lead to a full compromise of the website's data and user privacy.

Technical details

An SQL injection vulnerability exists in AiOPMSD Final 1.0.0 due to improper neutralization of special elements in SQL commands (CWE-89). The application fails to sanitize various GET parameters across multiple PHP files, including director.php (director parameter), actor.php (actor parameter), search.php (q parameter), and others (country, quality, year, genre, watch). An unauthenticated remote attacker can exploit this by sending crafted GET requests containing malicious SQL payloads. Successful exploitation allows the attacker to extract sensitive information from the database, such as database names, version details, and user credentials. No patch is currently known for this legacy software.

Affected products

  • hayinfx All in one pack Online Movie Streaming (AiOPMSD) 1.0.0 Final

Timeline

  • 2017-09-05: other: Last known software update (Final version build 4)
  • 2018-10-24: disclosed: Exploit-DB proof of concept published
  • 2026-05-30: advisory: CVE published and NVD record created

References

Related threats