[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Zenario CMS 8.8.53370 - (id) Blind SQL Injection Vulnerability

Author
Balaji Ayyasamy
Risk
[
Security Risk High
]
0day-ID
0day-ID-35945
Category
web applications
Date add
15-03-2021
Platform
php
# Exploit Title: Zenario CMS 8.8.53370 - 'id' Blind SQL Injection 
# Exploit Author: Balaji Ayyasamy
# Vendor Homepage: https://zenar.io/
# Software Link: https://github.com/TribalSystems/Zenario/releases/tag/8.8
# Version: 8.8.53370
# Tested on: Windows 10 Pro 19041 (x64_86) + XAMPP 7.4.14

# Reference - https://edhunter484.medium.com/blind-sql-injection-on-zenario-cms-b58b6820c32d

Step 1 - Login to the zenario cms with admin credentials.
Step 2 - Go to modules and select plugin library.
Step 3 - Select any plugin and press delete button. Copy the delete request and send it to the sqlmap.

Command - sqlmap -r request.txt -p id

#  0day.today [2024-11-15]  #