Description
Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Ahmet Ümit BAYRAM
References
www.exploit-db.com/exploits/46593 (ExploitDB-46593)
www.inoutscripts.com/products/inout-article-base/ (Official Product Homepage)
www.vulncheck.com/...stest-sql-injection-via-portallogin-php (VulnCheck Advisory: Inout Article Base CMS Lastest SQL Injection via portalLogin.php)