
CMS Made Simple < 2.2.10 - حقن SQL (مُعاد كتابته لـ Python 3)، CVE-2019-905
CMS Made Simple < 2.2.10 - حقن SQL (معاد كتابته لبايثون 3)، CVE-2019-9053
وجدت صعوبة في تشغيل هذه الأداة على كالي لينكس، لأن بايثون 2 لا يحتوي على termcolor، لذا مع تعديلات بسيطة جعلتها تعمل مع بايثون 3. جميع الحقوق تعود إلى: https://www.exploit-db.com/exploits/46635
لقد اختبرتها على جهاز CMS ضعيف على https://tryhackme.com . تعمل كما هو متوقع
┌──(xtafnull㉿kali)-[/opt]
└─$ python3 46635.py
[+] Specify an url target
[+] Example usage (no cracking password): exploit.py -u http://target-uri
[+] Example usage (with cracking password): exploit.py -u http://target-uri --crack -w /path-wordlist
[+] Setup the variable TIME with an appropriate time, because this sql injection is a time based.