Группа компаний "Сумотори" sql injection

2020.12.05
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

* Exploit Title: Группа компаний "Сумотори" sql injection * Google Dork: intext:" © 2020 Группа компаний "Сумотори" " inurl:id= * Date: 2020.12.04 * Exploit Author: OmideMehraban * Vendor Homepage: http://www.sumotori.ru/ * Software Link: http://www.sumotori.ru/ * Category : webapps * Version: 4.5.14 * Tested on: windows 7 , firefox ********************************************************* * Demo: * http://www.sumotori.ru/?id=14 * Add Single quotation ' to the last link ### Special Thanks: * Sk0t-V@hshAT ********************************************************* * Discovered By OmideMehraban * Instagram: @omidemehraban * Telegram: @omiid *********************************************************


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top