PHP Scripts Theater Management Script version 3.1.5 suffers from a remote SQL injection vulnerability.
# Exploit Title: PHP Scripts - Theater Management Script - SQL Injection
# Dork: inurl:show-time.php?moid=
# Date: 18.08.2017
# Vendor Homepage :
# Version: 3.1.5
# Category: Webapps
# Tested on: WiN10_x64 / KaLiLinux_x64
# CVE: N/A
# # # # # # # # # # # # #
# Exploit Author: AnGrY BoY
# Author Web:
# Author E-Mail: [email protected]
# # # # # # # # #
# Description:
# The vulnerability allows an attacker to inject sql commands....
# Proof of Concept:
# http://localhost/[PATH]/show-time.php?moid=[SQL]