SQL Injection Vulnerability in Mexican ISP
by v3nuzc0d3r2325 - Tuesday August 5, 2025 at 08:49 AM
#1
Hello everyone! This is my first post, where I want to share a very simple vulnerability I found at IZZI, one of the largest internet service providers in Mexico. To exploit it, you just need to access the login panel or the password recovery section, enter some fake credentials, capture the request with Burp Suite, and pass it to SQLMap. I was unsuccessful extracting the tables, possibly due to a bug in SQLMap. See:

https://github.com/sqlmapproject/sqlmap/issues/4613

If anyone manages to extract the tables, I'd love a direct message so we can work together and see what could have been done. This is not for profit or anything like that; it's just a vulnerability I wanted to share here.

https://imgur.com/a/8FeT7l5
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  REQUEST Full NationalPublicData with SSNs Instinct 6 690 40 minutes ago
Last Post: Rollinbk60
  TG @Fullzpros | SSN DOB DL-SIN-NIN FULLZ | DL-PASSPORT PHOTOS | CC DUMPS | LATEST TO Fullzpro 1 241 42 minutes ago
Last Post: Rollinbk60
  REQUEST SERASA EXPERIAN (DATABASE) Jllo12324 1 237 1 hour ago
Last Post: debutuca
Exclamation Mediaworks Hungary Zrt. Leak zorex4576 0 86 5 hours ago
Last Post: zorex4576
  I search admin page of 5 web sites selluk 0 87 6 hours ago
Last Post: selluk

Forum Jump:


 Users browsing this forum: 1 Guest(s)