Victor CMS sql注入漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

#### Exploit Title: Victor CMS 1.0 - Multiple SQL Injection (Authenticated) #### Date: 17.12.2020 #### Exploit Author: Furkan Göksel #### Vendor Homepage: https://github.com/VictorAlagwu/CMSsite #### Software Link: https://github.com/VictorAlagwu/CMSsite/archive/master.zip #### Version: 1.0 #### Description: The Victor CMS v1.0 application is vulnerable to SQL #### injection in c_id parameter of admin_edit_comment.php, p_id parameter #### of admin_edit_post.php, u_id parameter of admin_edit_user.php, edit #### parameter of admin_update_categories.php. #### Tested on: Apache2/Linux Step 1: Register the system through main page and login your account Step 2: After successful login, select one of the specified tabs (post, categories, comments, users) Step 3: When you click edit button of these records, an HTTP request is sent to server to get details of this record with corresponding parameters (eg. for edit comment it is c_id parameter) Step 4: Inject your SQL payload to these ids or...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息