vendor:
ImpressCMS
by:
Manuel García Cárdenas
N/A
CVSS
N/A
Time-based SQL Injection
89
CWE
Product Name: ImpressCMS
Affected Version From: ImpressCMS <= v1.3.9
Affected Version To: ImpressCMS <= v1.3.9
Patch Exists: YES
Related CWE: N/A
CPE: a:impresscms:impresscms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Time-based SQL Injection in Admin panel ImpressCMS <= v1.3.9
This bug was found using the portal with authentication as administrator. To exploit the vulnerability only is needed use the version 1.0 of the HTTP protocol to interact with the application. It is possible to inject SQL code in the variable 'quicksearch_mod_profile_Field' on the page '/modules/profile/admin/field.php'.
Mitigation:
Install vendor patch.