# Exploit Title: Simple Chat System 1.0 - 'id' SQL Injection # Dork: N/A # Date: 2018-10-24 # Exploit Author: Ihsan Sencan # Vendor Homepage: https://www.sourcecodester.com/php/11610/simple-chat-system.html # Software Link: https://sourceforge.net/projects/simple-chat-system/files/latest/download # Version: 1.0 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: N/A # POC: # 1) # http://localhost/[PATH]/user/chatroom.php?id=[SQL] # # [PATH]/user/chatroom.php # 03