# Exploit Title: SAUDI SOFTECH (MST) search.php SQL Injection & XSS
# Date: 04/04/2020
# Dork : intext: "Designed by SAUDI SOFTECH (MST) "
# Exploit Author: Blackmaster Hacker
# Vendor Homepage: https://www.saudisoftech.com
# Tested on: win,linux
# Poc:
http://www.wtgksa.com
############################## SQL Injection ##############################
1- go to
http://www.wtgksa.com/search.php
2- In the search bar type any word and after that put an apostrophe there will appear the SQL error message
3- Perform the Manual SQL injection
############################## XSS ##############################
1- go to
http://www.wtgksa.com/search.php
2- In the search bar type <script> alert("Blackmaster Told you that there is XSS ")</script>
3- an alert with the string will popup
############################## Contact me ##############################
Contact me :
Snapchat:
baraashudaifat
Telegram username :
bm_0r
Instagram:
bm_0r