Description
thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or modify database information.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Cakes
References
www.exploit-db.com/exploits/47581 (ExploitDB-47581)
github.com/thejshen/contentManagementSystem (Vendor Homepage)
www.vulncheck.com/.../thejshen-globitek-cms-id-sql-injection (VulnCheck Advisory: thejshen Globitek CMS 1.4 - 'id' SQL Injection)