Teachers record management system 1.0 searchteacher sql injection Vulnerability / Exploit
Exploits / Vulnerability Discovered : 2021-02-15 |
Type : webapps |
Platform : php
This exploit / vulnerability Teachers record management system 1.0 searchteacher sql injection is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: Teachers Record Management System 1.0 - 'searchteacher' SQL Injection
# Date: 13/02/2021
# Exploit Author: Soham Bakore, Nakul Ratti
# Vendor Homepage: https://www.sourcecodester.com/
# Software Link: https://www.sourcecodester.com/php/14399/teacher-record-system-phpmysql.html
# Version:1.0
# Tested on: latest version of Chrome, Firefox on Windows and Linux
--------------------------Proof of Concept-----------------------
1. Navigate to http://host/trms/
2. The "searchteacher" parameter in search-teacher.php is vulnerable to SQL
3. Below curl request will display the admin username and password hash