Beware: FengOffice’s Blind SQL Injection Vulnerability Exposed!
Unleash your inner hacker and tickle your funny bone with our guide to a Blind SQL Injection on FengOffice. Explore the thrilling world of injection points while sipping a latte and let SQLMap do all the heavy lifting. Spoiler: MySQL never saw it coming!

Hot Take:
FengOffice just got feng-shui’d into a state of chaos! With a blind SQL injection vulnerability, it’s like leaving the front door open and wondering why the fridge is empty. Time to feng-shui that code and lock it down!
Key Points:
- SQL Injection vulnerability in FengOffice, version 3.11.1.2.
- Exploited using SQLMap tool with specific parameters.
- Targets the “dim” parameter in the HTTP GET request.
- Tested successfully on Ubuntu 22.04.
- Back-end DBMS identified as MySQL version 5.7.37.
Already a member? Log in here