This exploit demonstrates a SQL injection vulnerability in SOPlanning 1.45 via the 'by' parameter in the OrderBy clause. It includes a captured HTTP request and instructions for using SQLMap to dump user credentials from the database.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target:SOPlanning 1.45
No auth needed
Prerequisites:Access to the target application · SQLMap installed