Seat reservation system 1.0 unauthenticated sql injection Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2020-10-16 |
Type : webapps |
Platform : php
This exploit / vulnerability Seat reservation system 1.0 unauthenticated sql injection is for educational purposes only and if it is used you will do on your own risk!
The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.