Advertisement






طراحی و تولید: " ایران سامانه High Security Level SQL Injection

CVE Category Price Severity
CVE-2021-1234 CWE-89 $500 High
Author Risk Exploitation Type Date
Anonymous High Remote 2017-04-07
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2017040028

Below is a copy:

  : "   High Security Level  SQL Injection##########################
# Exploit Title: High Level SQL Injection 
# Google Dork: intext:"  : "   " " intitle:
# Date: 2017-04-06
# Author: Mr.0&1 ( IR Independent Hacker )
# Software : None
# Version: all
# CVE : -
##########################

Description:

-----------------
Proof of concept : 

The  developers of those websites and their team  must've forgotten to check out the security level of  each code !
As I just mentioned earlier  , this type of attack  is sorta High and the whole database can be dumped  just by  using some bypass methods  .  Here I provided some  websites which are all vulnerable to SQL Injection . youcan dump the whole database of each website easily and if truth be known , username and password  can be shown less than a second  ... ( Hashes might be in SHA1 format ) so check that out ..

----------------------------------------
Demo : 

http://hadiesazan.ir/?category=14'

http://hadiesazan.ir/product_view.php?product_id=-7'

http://farsbtc.ir/language_news.php?news_id=3'


----------------------------------------
***************************************************************

Mr.0&1 IR Independent Hacker & security Researcher )

Wanna chit-chat ?  o.O 

# My Telegram :

https://t.me/GodBlessTheUnitedStatesOfAmerica

09367242182

****************************************************************



Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum