This exploit demonstrates SQL injection vulnerabilities in iTech Freelancer Script 5.27 via crafted UNION-based payloads targeting the 'profile.php' and 'showSkill.php' endpoints. The payloads extract database schema information using EXPORT_SET and other SQL functions.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target:iTech Freelancer Script 5.27
No auth needed
Prerequisites:Access to the vulnerable web application endpoints