Elkagroup - 'pid' SQL Injection
This exploit demonstrates a SQL injection vulnerability in the 'property.php' script of elkagroup.com's software. The PoC uses a UNION-based SQLi to extract usernames and passwords from the 'gallery_user' table.