# Exploit Title: Free and Open Source Inventory Management System 1.0 - Unauthenticated SQL Injection# Exploit Author: Sefa Ozan# Date: 16/09/2023# Vendor: MAYURIK# Vendor Homepage: https://mayurik.com/# Software Link: https://www.sourcecodester.com/php/16741/free-and-open-source-inventory-management-system-php-source-code.html# Tested on: Windows 10 Pro & Ubuntu 22.04## Description:The `pid[]` parameter is vulnerable to Time Based SQL injection attacks. To prove the existence of the vulnerability,