header-logo
Suggest Exploit
vendor:
CMS
by:
Kr4L BeNiM
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: CMS
Affected Version From: 4.x.x
Affected Version To: 4.x.x
Patch Exists: N/A
Related CWE: N/A
CPE: mambo-developer.org
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011

CMS 4.x.x Zorder (SQL Injection Vul)

The 'zorder' parameter was not properly sanitized upon submission to the administrator/index2.php url, which allows attacker to conduct SQL Injection attack.

Mitigation:

Input validation and sanitization should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

*####################################################################
[+] Exploit Title : CMS 4.x.x Zorder (SQL Injection Vul)
[+] Author : Kr4L BeNiM
[+] Contact : www.facebook.com/kr4l.hacker
[+] Date : November 13, 2011
[+] Software Link:  http://mambo-developer.org
[+] Category: Web Apps
####################################################################

Vulnerability:

*SQL injection Vulnerability*

[#]  Exploit : -

The "zorder" parameter was not properly sanitized upon submission to
the administrator/index2.php url, which allows attacker to conduct
SQL Injection attack.


[#] Explaination : -

http://target.com/mambo/administrator/index2.php?limit=10&order[]=11&boxchecked=0&toggle=on&search=sqli&task=&limitstart=0&cid[]=on&zorder=
(SQL Inj Codes)

####################################################################
[+] Greets : Likuid Sky, Hax.Root, S.O.G, DjArs HaXoR, KiLLerMiNd, CyberLeeTs
####################################################################