CMS Wizard SQL Injection

2012.06.09
Credit: Mr.Gh0st
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

Title : CMS Wizard SQL Injection Vulnerbility Date : 7th June 2012 Author : Mr.Gh0st [Cyb3r.pr3dat0r@gmail.com] Vendor : http://www.cmswizard.co.uk/ Dork : intext:Powered by CMS Wizard inurl:shop.php?viewcategory= Tested On :Arch Linux P0c : /shop.php?viewcategory=104' Demo Site : http://www.baby-basket.co.uk/shop.php?viewcategory=104' http://www.homesweethomestyle.co.uk/shop.php?viewcategory=104' http://www.csm.org.uk/shop/shop.php?viewcategory=30' Shoutz : Infam0us , Golden BoY , s3v3n , Vanish3r , ph4nt0mc0d3r , 0xHAT and all other members of www.code104.net

References:

http://www.cmswizard.co.uk/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top