News Website Script 2.0.4 – ‘search’ SQL Injection

  • 作者: Varun Bagaria
    日期: 2018-02-13
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/44030/
  • ##################################################################
    # Exploit Title:News Website Script - SQL Injection (Error Based)
    # Google Dork: NA
    # Date: 12.02.2018
    # Exploit Author: Varun Bagaria
    # Vendor Homepage: https://www.phpscriptsmall.com/
    # Software Link: *http://under24usd.com/demo/newstoday/index.php
    # Version: 2.0.4
    # Tested on: Windows 7
    # Category: Webapps
    # CVE : NA
    ##################################################################
    
    Proof of Concept
    =================
    
    Attack Parameter : search
    Payload : '
    
    Reproduction Steps:
    ------------------------------
    1. Access the script
    2. In the search bar insert ' and you will get error based SQL Injection