Testa online test management system 3.4.7 q sql injection Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2020-12-04 |
Type : webapps |
Platform : multiple
This exploit / vulnerability Testa online test management system 3.4.7 q sql injection is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: Testa Online Test Management System 3.4.7 - 'q' SQL Injection
# Date: 2020-07-21
# Google Dork: N/A
# Exploit Author: Ultra Security Team
# Team Members: Ashkan Moghaddas , AmirMohammad Safari , Behzad Khalifeh , Milad Ranjbar
# Vendor Homepage: https://testa.cc
# Version: v3.4.7
# Tested on: Windows/Linux
# CVE: N/A
.:: Description ::.
Testa Helps You To make Online Exams.
.:: Proof Of Concept (PoC) ::.
Step 1 - Find Your Target Using Testa - Online Test Management System.
Step 2 - Click on List And Search Exams.
Step 3 - Inject Your Payloads in Search Field.