header-logo
Suggest Exploit
vendor:
Smart Cart
by:
D4rk357
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Smart Cart
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Pre E smart cart authentication bypass

On the login page, an attacker can enter 'admin' as the username and 'or '1'='1' as the password to bypass authentication.

Mitigation:

Ensure that authentication is properly implemented and that user input is properly validated.
Source

Exploit-DB raw data:

#################################################################
# Exploit Title:Pre E smart cart  authentication bypass

# Date: 16th july 2010

# Author: D4rk357

#Critical:high

#contact:d4rk357[at]yahoo[dot]in

Price : 49$

# Software Link:http://preproject.com/smartcart.asp
 
Greetz to :b0nd, Fbih2s,Beenu,rockey killer,The empty(), punter,eberly,prashant

Shoutz to : http://www.garage4hackers.com/forum.php , h4ck3r.in and  all ICW members
 
##############################################################################
Exploit : On login page put admin and usename and ' or '1'='1 as password . 
you will be logged into the system

 ##################################################################################
 #D4rk357