Advertisement






SAUDI SOFTECH (MST) search.php Sql injection

CVE Category Price Severity
N/A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') $500 High
Author Risk Exploitation Type Date
Unknown Critical Remote 2020-04-04
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 0.10607 0.655

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020040021

Below is a copy:

SAUDI SOFTECH (MST) search.php Sql injection
# Exploit Title: SAUDI SOFTECH (MST)  search.php SQL Injection & XSS 
# Date: 04/04/2020
# Dork : intext: "Designed by SAUDI SOFTECH (MST) "
# Exploit Author: Blackmaster Hacker
# Vendor Homepage: https://www.saudisoftech.com
# Tested on: win,linux

# Poc:

http://www.wtgksa.com
############################## SQL Injection  ##############################
1- go to 
http://www.wtgksa.com/search.php
2- In the search bar type any word and after that put an apostrophe there will appear the SQL error message 
3-  Perform the Manual SQL injection 
############################## XSS ##############################
1- go to 
http://www.wtgksa.com/search.php
2- In the search bar type  <script> alert("Blackmaster Told you that there is XSS ")</script> 
3-  an alert with the string will popup  
############################## Contact me ############################## 
Contact me :
Snapchat:
baraashudaifat
Telegram username :
bm_0r
Instagram:
bm_0r 

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum