Local services search engine management system (lssmes) 1.0 blind & error based sql injection (authenticated) Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2021-03-03 |
Type : webapps |
Platform : php
This exploit / vulnerability Local services search engine management system (lssmes) 1.0 blind & error based sql injection (authenticated) is for educational purposes only and if it is used you will do on your own risk!
*Steps to Reproduce:*
1) Login with Admin Credentials and click on the *Service Category* button.
2) Click on the *Manage Category* button.
3) Now add the double quote ( " ) in the URL after *editid parameter*
4) At that time we observe that the application is misbehaving now capture this request from the burp suite and save it into an SQL text file.
4) Now fire up the following command into SQLMAP