Description
TheJshen ContentManagementSystem 1.04 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to extract or manipulate database information by crafting malicious query payloads.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Cakes
References
www.exploit-db.com/exploits/47569 (ExploitDB-47569)
github.com/thejshen/contentManagementSystem (Vendor Homepage)
www.vulncheck.com/...ontentmanagementsystem-id-sql-injection (VulnCheck Advisory: TheJshen contentManagementSystem 1.04 - 'id' SQL Injection)