Exploits / Vulnerability Discovered : 2018-11-26 |
Type : webapps |
Platform : php
This exploit / vulnerability Nocms 1.0 order_by sql injection is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: No-Cms 1.0 - 'order_by' SQL Injection
# Date: 2018-11-28
# Exploit Author: Loading Kura Kura
# Vendor Homepage: https://github.com/goFrendiAsgard/No-CMS
# Software Link: https://codeload.github.com/goFrendiAsgard/No-CMS/zip/master
# Tested on: Win10/Kali Linux
# Google Dork: n/a
# Version: n/a
# CVE :
# No-CMS is a CMS-framework.
# No-CMS is a basic and "less-assumption" CMS with some default features such as
# user authorization (including third party authentication), menu, module and theme management.
# It is fully customizable and extensible, you can make your own module and your own themes.
# It provide freedom to make your very own CMS, which is not provided very well by any other CMS.