This exploit demonstrates SQL injection vulnerabilities in EzInvoice 6.0.2, including a UNION-based SQLi in editclient.php and an authentication bypass in index.php. The PoC provides specific payloads for data extraction and bypass techniques.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:EzInvoice - Invoice Management System 6.0.2
No auth needed
Prerequisites:Access to the target web application