Saturday, December 4, 2010

SQL bug in Madurai kamraj university site!

SQL injection discovered  by Hussain , on Madurai Kamraj University site , this allow the user to see the results of all students without specifying  a register number .

POC:

1. link : http://www.mkuniversity.org/results_new.php

2. Select any course , instead of register number copy and paste this code and press get results button .




3.You can see results of all student without requiring  a register number , this works on similar site , to bypass authentication.


this injection can be also used to insert malicious sql command which can delete all the marks of the student from the database . :(


Enjoy .

0 comments:

Post a Comment

Twitter Delicious Facebook Digg Stumbleupon Favorites More

 
Design by Free WordPress Themes | Bloggerized by Lasantha - Premium Blogger Themes | Best Web Host