# Exploit title: SQL Injection Vulnerability in " Powered By ALFINE IT Solution " # # Exploit Author: Mehdi Razmjoo ( razmjumehdi@gmail.com ) # # CWE : CWE-89 # # Vendor Homepage: http://www.alfinesolutions.com # # Dork: - # # Date: 03-26-2018 # # Category: Web Application # # ============================= # # Description: # # The vulnerability allows a bad guy to inject sql commands. # # # Proof of Concept: # # http://Server/gallery.php?id=[SQLi] # #