======================================== ===========================================================================================
| # Title : Esg 2.5 Sql Injection Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 103.0(64-bit) |
| # Vendor : https://www.creatop.com.tw/esg |
| # Dork : Powered by CREATOP |
===========================================================================================

poc :


[+] Dorking Ä°n Google Or Other Search Enggine.

[+] Use Payload : news.php?tayear=2023

[+] http://www.127.0.0.1/vitaltec.com.tw/en/news/news.php?tayear=2023 <==== inject here

[+] Panel : /admin/login.php



Greetings to :=========================================================================================================================
|
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* moncet |
|
=======================================================================================================================================