SQL Injection Vulnerability in Mexican ISP
by v3nuzc0d3r2325 - Tuesday August 5, 2025 at 08:49 AM
#1
Hello everyone! This is my first post, where I want to share a very simple vulnerability I found at IZZI, one of the largest internet service providers in Mexico. To exploit it, you just need to access the login panel or the password recovery section, enter some fake credentials, capture the request with Burp Suite, and pass it to SQLMap. I was unsuccessful extracting the tables, possibly due to a bug in SQLMap. See:

https://github.com/sqlmapproject/sqlmap/issues/4613

If anyone manages to extract the tables, I'd love a direct message so we can work together and see what could have been done. This is not for profit or anything like that; it's just a vulnerability I wanted to share here.

https://imgur.com/a/8FeT7l5
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Vulnerability of SQL injection databases cybershadow404 7 2,233 02-06-2025, 11:21 AM
Last Post: selluk
  SQL Vulnerability / QUESTIONS cybershadow404 10 1,436 01-10-2025, 04:31 PM
Last Post: AnotherMember
  [REQUEST] Mexican AT&T database reverse69 5 5,692 09-07-2024, 08:38 AM
Last Post: All3in
  Mexican Voters 91M .. 2016 cafeciano 0 1,030 07-29-2024, 04:09 AM
Last Post: cafeciano
  FW-ecology-SQL-Injection: browser.jsp takashima888 0 2,922 07-18-2023, 09:49 AM
Last Post: takashima888

Forum Jump:


 Users browsing this thread: