vendor:
Morcego CMS
by:
darkjoker
7,5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Morcego CMS
Affected Version From: 1.7.6
Affected Version To: 1.7.6
Patch Exists: YES
Related CWE: N/A
CPE: a:morcego_cms:morcego_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Morcego CMS <= 1.7.6 Blind SQL Injection Exploit
Morcego CMS is vulnerable to Blind SQL Injection. This exploit allows an attacker to extract the password of a given user from the database. The exploit works by sending a crafted HTTP request to the vulnerable application and analyzing the response. If the response contains the application's title, then the crafted request was successful and the character is extracted from the database.
Mitigation:
Upgrade to the latest version of Morcego CMS.