vendor:
Blue Eye CMS
by:
darkjoker
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Blue Eye CMS
Affected Version From: 1.0.0
Affected Version To: 1.0.0
Patch Exists: YES
Related CWE: N/A
CPE: a:blue_eye_cms:blue_eye_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Blue Eye CMS <= 1.0.0 Blind SQL Injection Exploit
This exploit is used to find the sha1 hash of the password of a user in Blue Eye CMS <= 1.0.0. It uses a blind SQL injection vulnerability to find the password of the user. The exploit takes the hostname, path and username as arguments and finds the sha1 hash of the password of the user.
Mitigation:
The user should update to the latest version of Blue Eye CMS.