SQL Injection Vulnerability in Mexican ISP
by v3nuzc0d3r2325 - Tuesday August 5, 2025 at 08:49 AM
#1
Hello everyone! This is my first post, where I want to share a very simple vulnerability I found at IZZI, one of the largest internet service providers in Mexico. To exploit it, you just need to access the login panel or the password recovery section, enter some fake credentials, capture the request with Burp Suite, and pass it to SQLMap. I was unsuccessful extracting the tables, possibly due to a bug in SQLMap. See:

https://github.com/sqlmapproject/sqlmap/issues/4613

If anyone manages to extract the tables, I'd love a direct message so we can work together and see what could have been done. This is not for profit or anything like that; it's just a vulnerability I wanted to share here.

https://imgur.com/a/8FeT7l5
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Hey aksaity 0 58 2 hours ago
Last Post: aksaity
  Request for South Korea databases. AmazonsGoat 1 312 Yesterday, 03:45 AM
Last Post: minituktuk
  REQUEST South Africa JD Group database phas3lock 2 168 May 06, 2026, 07:30 PM
Last Post: phas3lock
  I search admin page of 5 web sites selluk 4 239 May 06, 2026, 03:33 PM
Last Post: selluk
  ANY SPAIN MOBILE DATABASE? IBERIA AIRLINES? darkbigfoot 3 199 May 06, 2026, 12:58 PM
Last Post: Theblueanonymouse

Forum Jump:


 Users browsing this forum: 1 Guest(s)