This exploit demonstrates a SQL injection vulnerability in PHP-MySQL-Quiz, allowing an attacker to extract sensitive database information such as user credentials, database version, and database name via a crafted UNION-based SQLi payload.
Classification
Working Poc 90%
Target:
PHP-MySQL-Quiz (version unspecified)
No auth needed
Prerequisites:
Target application must be accessible · Target must be using vulnerable version of PHP-MySQL-Quiz