关键信息 Vulnerability: - Type: Blind SQL Injection - Target: SmartBlog 2.0.1 - Affected Parameter: - Controller: - Platform: PHP - Vulnerable App: SmartBlog Exploit Details: - Exploit-ID: 48995 - CVE: N/A - Author: CWnUTS - Date: 2020-11-06 - Tested on: Linux Description: - Blind SQL Injection is present in the parameter of the controller. The vulnerability allows an attacker to extract information from the database by performing successive character tests. Proof of Concept (POC): - URL: - Script provided in the screenshot demonstrates how to exploit the vulnerability to extract information from the database. Vendor Homepage: