SQL Injection Vulnerability in Mexican ISP
by v3nuzc0d3r2325 - Tuesday August 5, 2025 at 08:49 AM
#1
Hello everyone! This is my first post, where I want to share a very simple vulnerability I found at IZZI, one of the largest internet service providers in Mexico. To exploit it, you just need to access the login panel or the password recovery section, enter some fake credentials, capture the request with Burp Suite, and pass it to SQLMap. I was unsuccessful extracting the tables, possibly due to a bug in SQLMap. See:

https://github.com/sqlmapproject/sqlmap/issues/4613

If anyone manages to extract the tables, I'd love a direct message so we can work together and see what could have been done. This is not for profit or anything like that; it's just a vulnerability I wanted to share here.

https://imgur.com/a/8FeT7l5
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  China identity cards database size: composed 7z formats 800 MB gravenet 0 130 Yesterday, 06:30 AM
Last Post: gravenet
  Hey aksaity 1 144 Yesterday, 04:26 AM
Last Post: Crimesz
  REQUEST Darkthrone.com db spazz1x 1 115 Yesterday, 04:03 AM
Last Post: Crimesz
  Request for South Korea databases. AmazonsGoat 1 344 May 07, 2026, 03:45 AM
Last Post: minituktuk
  REQUEST South Africa JD Group database phas3lock 2 194 May 06, 2026, 07:30 PM
Last Post: phas3lock

Forum Jump:


 Users browsing this forum: 1 Guest(s)