This is a functional SQL injection exploit for Vastal I-Tech software, demonstrating how to extract admin credentials via a crafted HTTP request. The exploit targets the 'group_id' parameter in 'view_group.php' and includes a sample payload for data exfiltration.
Classification
Working Poc 90%
Target:
Vastal I-Tech (version unspecified)
No auth needed
Prerequisites:
Access to the target web application · SQL injection vulnerability in 'view_group.php'