Exploits / Vulnerability Discovered : 2021-10-25 |
Type : webapps |
Platform : php
This exploit / vulnerability Engineers online portal 1.0 multiple authentication bypass is for educational purposes only and if it is used you will do on your own risk!
Technical description:
An SQL Injection vulnerability exists in the Engineers Online Portal login form which can allow an attacker to bypass authentication.
Steps to exploit:
1) Navigate to http://localhost/nia_munoz_monitoring_system/login.php
2) Insert your payload in the user or password field
3) Click login
Proof of concept (Poc):
The following payload will allow you to bypass the authentication mechanism of the Engineers Online Portal login form -
' OR '1'='1';-- -