This is a writeup describing a SQL injection vulnerability in K-Rate's view.php via the 'username' parameter. The exploit requires appending '.html' to bypass mod_rewrite rules on Apache.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:K-Rate (version unspecified)
No auth needed
Prerequisites:Apache with mod_rewrite enabled · K-Rate installation with view.php accessible