CMS 4.x.x Zorder (SQL Injection Vul)



EDB-ID: 18110 CVE: 2011-2917 OSVDB-ID: 74502
Author: KraL BeNiM Published: 2011-11-13 Verified: Not Verified
Exploit Code:   Download Vulnerable App:    Download

Rating

(0.0)
Prev Home Next
*####################################################################
[+] Exploit Title : CMS 4.x.x Zorder (SQL Injection Vul)
[+] Author : Kr4L BeNiM
[+] Contact : www.facebook.com/kr4l.hacker
[+] Date : November 13, 2011
[+] Software Link:  http://mambo-developer.org
[+] Category: Web Apps
####################################################################

Vulnerability:

*SQL injection Vulnerability*

[#]  Exploit : -

The "zorder" parameter was not properly sanitized upon submission to
the administrator/index2.php url, which allows attacker to conduct
SQL Injection attack.


[#] Explaination : -

http://target.com/mambo/administrator/index2.php?limit=10&order[]=11&boxchecked=0&toggle=on&search=sqli&task=&limitstart=0&cid[]=on&zorder=
(SQL Inj Codes)

####################################################################
[+] Greets : Likuid Sky, Hax.Root, S.O.G, DjArs HaXoR, KiLLerMiNd, CyberLeeTs
####################################################################