Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:27353
HistoryNov 27, 2011 - 12:00 a.m.

AdaptCMS 2.x SQL Injection Vulnerability

2011-11-2700:00:00
vulners.com
40

=========================================================================
AdaptCMS 2.x SQL Injection Vulnerability

:-------------------------------------------------------------------------------------------------------------------------:
: # Exploit Title : AdaptCMS 2.x SQL Injection Vulnerability
: # Date : 23 November 2011
: # Author : X-Cisadane
: # Software Link : http://www.adaptcms.com
: # Version : 2.0.0 and 2.0.1
: # Category : Web Applications
: # Vulnerability : SQL Injection
: # Tested On : Google Chrome 14.0.835 (Windows)
: # Dorks : intext:"Powered by AdaptCMS" OR Powered by AdaptCMS
: # Greetz to : X-Code, Muslim Hackers, Depok Cyber, Hacker Cisadane,
Borneo Crew,
Dunia Santai, Jiban Crew, Winda Utari, Anharku, Array XCrew, Remick
Kuzmanovic

:-------------------------------------------------------------------------------------------------------------------------:

POC :
SQL Injection Vulnerability

Warning: mysql_fetch_row(): supplied argument is not a valid MySQL result
resource in /home/victim site/public_html/directory/config.php on line 262

Warning: mysql_num_rows(): supplied argument is not a valid MySQL result
resource in /home/victim site/public_html/directory/config.php on line 293

-= Regards =-
Dwi a.k.a X-Cisadane