################################################################## # Exploit Title:News Website Script - SQL Injection (Error Based) # Google Dork: NA # Date: 12.02.2018 # Exploit Author: Varun Bagaria # Vendor Homepage: https://www.phpscriptsmall.com/ # Software Link: *http://under24usd.com/demo/newstoday/index.php # Version: 2.0.4 # Tested on: Windows 7 # Category: Webapps # CVE : NA ################################################################## Proof of Concept ================= Attack Parameter : search Payload : ' Reproduction Steps: ------------------------------ 1. Access the script 2. In the search bar insert ' and you will get error based SQL Injection