vendor:
UliCMS
by:
Manuel García Cárdenas
7,1
CVSS
HIGH
Time-based SQL Injection
89
CWE
Product Name: UliCMS
Affected Version From: UliCMS <= v9.8.1
Affected Version To: UliCMS <= v9.8.1
Patch Exists: YES
Related CWE: N/A
CPE: a:ulicms:ulicms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Time-based SQL Injection in Admin panel UliCMS <= v9.8.1
This bug was found using the portal with authentication as administrator. To exploit the vulnerability only is needed use the version 1.0 of the HTTP protocol to interact with the application. It is possible to inject SQL code in the variable 'country_blacklist' on the page 'action=spam_filter'.
Mitigation:
Install vendor patch.