# Exploit Title: Simple POS and Inventory 1.0 - 'cat' SQL Injection # Dork: N/A # Date: 2018-10-24 # Exploit Author: Ihsan Sencan # Vendor Homepage: https://www.sourcecodester.com/php/11625/simple-pos-and-inventory-system.html # Software Link: https://sourceforge.net/projects/simple-pos-and-inventory/files/latest/download # Version: 1.0 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: N/A # POC: # 1) # http://localhost/[PATH]/user/plist.php?cat=[SQL] # # [PATH]/user/plist.php # # 03 # 04 # 05 # 06
# 07 # 08
# 09
# 10 # 04 # 05 # 06
# 07 # 08
# 09
# 10