Elevel SQL INJECTION VULNERABILITY - Noob Exploded

Blogging , Defacing , Pentesting , News Hacking

Saturday, 13 May 2017

Elevel SQL INJECTION VULNERABILITY


Exploit Title : Elevel SQL INJECTION VULNERABILITY
Google Dork : intext:"Web Design by Elevel"
Date : 12/05/2017
Exploit Author : Mohammad Babaee
Vendor Homepage : https://www.elevel.it/
Software Link : https://www.elevel.it/
Version : 2.0
Tested on : Windows10 , Firefox

################################################################


Proof of concept : Elevel SQL INJECTION

1 - Search this Google Dork : intext:"Web Design by Elevel"
2 - Find Websites With SQL INJECTION BUG
3 - Open One of them ( Random )
4 - Attention to end of URL , with number value Like: ( .php?id=549 )
5 - Start Your injection Attack
6 - The End , Enjoy Of Hacking ...!

DEMO :

https://www.pancar.it/multimedia.php?id=4' [SQL INJECTION VULNERABILITY]

https://www.siatautomazioni.it/news_dettaglio.php?id=22' [SQL INJECTION VULNERABILITY]

No comments:

Post a Comment