This is a writeup describing a SQL injection vulnerability in ShopSystem's view_image.php via the 'id' parameter. It provides an example exploit URL to extract the database name but does not include executable exploit code.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:ShopSystem (versions unknown)
No auth needed
Prerequisites:Access to the vulnerable ShopSystem instance · MySQL database backend