Thread: 80k Email DB
View Single Post
  #1  
Old 01-10-2025, 01:23 AM

Elusive Elusive is offline
Banned
Join Date: Jun 2023
Posts: 1
Default


Fresh DB - SQLi - 80k Email
Code:
http://agrocentro.net/index.php?sec=contactenos'

Found character insertion [-1'] in place of [contactenos'] to detect error on ORDER BY
Add manually the character * like [contactenos'*] to force the value [contactenos']
Vulnerable to GROUPBY::floor_rand using 60 characters
Vulnerable to XML::extractvalue using 27 characters
Database [agro_db] on MySQL [5.1.73-community] for user [agro_user2@localhost]