Online-Exam-System
cpe:2.3:a:online_exam_system_project:online_exam_system:*:*:*:*:*:*:*
- 2015
A time-based blind SQL injection vulnerability has been identified in the Online Exam System 2015, specifically within the feedback form. This vulnerability allows attackers to extract database password hashes by exploiting the 'feed.php' endpoint. The exploitation involves sending crafted payloads that use time delays to systematically enumerate password characters.
Exploitation of this vulnerability allows for time-based blind SQL injection, where an attacker can extract password hashes from the database.
To reproduce this vulnerability, send a POST request to the 'feed.php' endpoint with a payload that includes a SQL injection payload designed to exploit time-based blind SQL injection. The payload should be crafted to use time delays to enumerate password characters. Monitor the response time to determine if the injection was successful.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.