
Python 3 exploit for CVE-2019-9053, an unauthenticated time-based blind SQL injection in CMS Made Simple < 2.2.10, extracting admin credentials and optionally cracking password hashes.
Author: Daniele Scanu
Reference: Exploit-DB 46635
CVE: CVE-2019-9053
⚠️ Disclaimer: This script is for educational and authorized testing purposes only. Do not use it on systems you do not own or have explicit permission to test. The author and contributors are not responsible for any misuse or damage caused by this tool.
This is a Python 3 exploit script for the Unauthenticated SQL Injection vulnerability in CMS Made Simple versions < 2.2.10. It automates the extraction of sensitive information (salt, username, email, password hash) from a vulnerable CMS instance using a time-based blind SQL injection.
python cms_exploit.py -u http://target-uri
To attempt password cracking with a wordlist:
python cms_exploit.py -u http://target-uri --crack -w /path/to/wordlist.txt
python cms_exploit.py -u http://10.10.10.100/cms
requests librarytermcolor libraryInstall dependencies with:
pip install requests termcolor
The script provides a colorful, step-by-step output of the extraction and cracking process, making it both informative and fun to watch!
This script is a great way to learn about SQL injection, time-based attacks, and password cracking. Use it responsibly, and always with permission!
This project is for educational use only. No warranty, no guarantees. Have fun, hack ethically, and stay curious!