#Date 18.01.2020 #Author : CyberFlash #Vuln : boolean-based blind, error-based,time-based blind Sqli in "TAGWORX.CMS 3.30.00 - 3.50.00" #Vuln : /ynews.php?cid=[Inject Here] #Vendor : https://www.tagworx.net/ #Dork : intext:"Driven by TAGWORX.CMS" inurl:"/ynews.php?cid=" #Ältere Vulns : https://cyber.vumetric.com/vulns/CVE-2008-2394/sql-injection-vulnerability-in-tagworx-cms-3-00-02/ Bsp. Vuln's : https://www.laimer-historiker.de/ynews.php?cid=%274&pid=4 [V=3.30.00] https://www.maler-weim.de/ynews.php?cid=%274&pid=4 [V=3.50.00]
Bearbeitet von CyberFlash, 19 January 2020 - 14:08 Uhr.