This exploit demonstrates a SQL injection vulnerability in PHP-Lance 1.52 via the 'subcat' parameter. The PoC includes a crafted SQL query that extracts table and column names from the database.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target:PHP-Lance 1.52
No auth needed
Prerequisites:Access to the vulnerable web application