VehicleWorkshop Authentication Bypass / SQL Injection

VehicleWorkshop suffers from a remote SQL injection vulnerability that allows for authentication bypass.

MD5 | 64764044ccdef8622fdfc659f7902ff2

[*] Type: Admin or Customer login bypass via SQL injection
[*] Author: Touhid M.Shaikh
[*] Vendor Homepage:
[*] Mail: touhidshaikh22[at]gmail[dot]com
[*] More info:


===================== PoC ================

Admin Login Page :
Customer Login Page :

Navigate admin login page or Customer Login Page and submit ' OR 1 --+ for
username and password

and it should give you access to the admin area or Customer Area.

Touhid Shaikh

Related Posts