Description
Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract database information using time-based blind techniques. Attackers can exploit the v parameter with sleep-based blind injection to confirm vulnerability and extract data.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Borna nematzadeh (L0RD) or borna.nematzadeh123@gmail.com
References
www.exploit-db.com/exploits/44685 (ExploitDB-44685)
bylancer.com (Official Product Homepage)
www.vulncheck.com/...ection-via-v-parameter-time-based-blind (VulnCheck Advisory: Zechat 1.5 SQL Injection via v parameter (time-based blind))