This exploit demonstrates a SQL injection vulnerability in MMA Creative Design's software, specifically targeting the 'id' parameter in 'page.php'. The provided demo URL shows a UNION-based SQL injection to extract user credentials from the 'users' table.
Classification
Working Poc 90%
Target:
MMA Creative Design (version unspecified)
No auth needed
Prerequisites:
A vulnerable installation of MMA Creative Design software · Access to the 'page.php' endpoint with an injectable 'id' parameter