Account Take Over Vulnerability in a Pizza website ( I hacked into its Database)

Harshit
Nov 4, 2020

--

I’m going to share this concise writeup for a bug reported to the pizza website. The bug was a very Straight Forward, but there was an obstacle that could prevent it from being discovered.
After searching for bugs on the that website, I found a parameter on the that website, and as usual directly gave the string behind the parameter of the website, and it is true that the website is directly error.

After inserting the payload on the website that is correct” vuln with SQL INJECTION, and release the existing database on the website.

--

--

Harshit
Harshit

Written by Harshit

Security researcher |Android Developer | EE | Bug Bounty Hunter | Reverse Engineering | Malware analyst

No responses yet