vendor:
Lizardware CMS
by:
athos
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Lizardware CMS
Affected Version From: 0.6.0
Affected Version To: 0.6.0
Patch Exists: Yes
Related CWE: N/A
CPE: a:lizardware:lizardware_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Lizardware CMS <= 0.6.0 Blind SQL Injection Exploit
This exploit is used to gain access to the Lizardware CMS version 0.6.0 and below. It uses a blind SQL injection vulnerability to gain access to the user table in the database. The exploit takes three parameters: the domain, the table prefix, and the user ID. It then uses a loop to iterate through the characters of the user's password, sending a request for each character. If the response time is greater than 6 seconds, the character is added to the password string.
Mitigation:
Upgrade to the latest version of Lizardware CMS and ensure that all security patches are applied.