Construction Company of Mellat Bank Sql Injection Vulnerability

Published
Credit
Risk
2015.11.21
4TT4CK3R
Medium
CWE
CVE
Local
Remote
CWE-89
N/A
No
Yes

[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+]
~# : Exploit title : Construction Company of Mellat Bank Sql Injection Vulnerability
~# : Exploit Author : 4TT4CK3R
~# : Vendor HomePage : http://www.mellatmcc.ir
~# : Date : 2015/11/19
~# : Tested on : Kali Linux , Mozilla Firefox , Windows
~# : Google Dork : No
~# : Location : http://www.mellatmcc.ir/pages.php?pageID=2
[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+]

~# : Description >>
Construction Company of Mellat Bank have a Sql Injection Vulnerability on the page pages.php and id=2 !
To test the vulnerability you can add ' at the end of this address :
http://www.mellatmcc.ir/pages.php?pageID=2
You seeing that Mysql error Will occur !!

~# : ScreenShot : http://i.imgur.com/wHWm0JQ.png

[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+]

~# : Discovered by : 4TT4CK3R
~# : We Love Islamic Republic of Iran

[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+]

References:

http://i.imgur.com/wHWm0JQ.png


See this note in RAW Version

 
Bugtraq RSS
Bugtraq
 
CVE RSS
CVEMAP
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn


Copyright 2017, cxsecurity.com