
Python 3 exploit for CVE-2019-9053, an unauthenticated SQL injection in CMS Made Simple 2.2.9, that extracts admin credentials and optionally cracks password hashes.
This repository provides a Python 3 compatible exploit targeting an unauthenticated SQL injection vulnerability in CMS Made Simple versions 2.2.9 and earlier. The flaw, tracked as CVE-2019-9053, allows attackers to extract sensitive administrator data, including username, hashed password, email, and salt.
The original exploit was authored by Daniele Scanu.
Original Exploit : https://www.exploit-db.com/exploits/46635
By using this script, you agree to:
Use it only on systems you own or have explicit permission to test. Not hold the author or contributors liable for any direct, indirect, or consequential damages resulting from its use.
To run the exploit and retrieve information about the CMS administrator without attempting to crack the password:
python3 CVE-2019-9053.py -u http://<TARGET-IP>/writeup
python3 CVE-2019-9053.py -u http://<TARGET-IP>/writeup --crack -w /usr/share/wordlists/rockyou.txt