SAUDI SOFTECH (MST) search.php Sql injection

2020.04.04
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

# Exploit Title: SAUDI SOFTECH (MST) search.php SQL Injection & XSS # Date: 04/04/2020 # Dork : intext: "Designed by SAUDI SOFTECH (MST) " # Exploit Author: Blackmaster Hacker # Vendor Homepage: https://www.saudisoftech.com # Tested on: win,linux # Poc: http://www.wtgksa.com ############################## SQL Injection ############################## 1- go to http://www.wtgksa.com/search.php 2- In the search bar type any word and after that put an apostrophe there will appear the SQL error message 3- Perform the Manual SQL injection ############################## XSS ############################## 1- go to http://www.wtgksa.com/search.php 2- In the search bar type <script> alert("Blackmaster Told you that there is XSS ")</script> 3- an alert with the string will popup ############################## Contact me ############################## Contact me : Snapchat: baraashudaifat Telegram username : bm_0r Instagram: bm_0r


Vote for this issue:
0%
100%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2020, cxsecurity.com

 

Back to Top