Exploits / Vulnerability Discovered : 2021-12-14 |
Type : webapps |
Platform : php
This exploit / vulnerability Online thesis archiving system 1.0 sqli authentication bypass is for educational purposes only and if it is used you will do on your own risk!
- Description:SQLi Authentication Bypass
SQL Injection vulnerability exists in Online Thesis Archiving System 1.0 1.0. An admin account takeover exists with the payload: admin' # - admin' or '1'='1
- Description: Stored Cross Site Scripting (XSS)
Stored Cross Site Scripting (XSS) exists in Online Thesis Archiving System 1.0.
Steps:
1- Go to (http://localhost/otas/admin/?page=departments) and (http://localhost/otas/admin/?page=curriculum)
2- Add new (curriculum) or (department)
3- Insert your payload <script>("xssyf")</script>
Online thesis archiving system 1.0 sqli authentication bypass