CMS Made Simple(CMSMS)是CMSMS团队的一套开源的内容管理系统(CMS)。该系统支持基于角色的权限管理系统、基于向导的安装与更新机制、智能缓存机制等。 CMSMS 2.2.8版本中存在SQL注入漏洞,该漏洞源于基于数据库的应用缺少对外部输入SQL语句的验证。攻击者可利用该漏洞执行非法SQL命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | This is modified code of 46635 exploit from python2 to python3. | https://github.com/SUNNYSAINI01001/46635.py_CVE-2019-9053 | POC Details |
| 2 | None | https://github.com/crypticdante/CVE-2019-9053 | POC Details |
| 3 | update to Daniele Scanu's SQL Injection Exploit - CVE-2019-9053 | https://github.com/maraspiras/46635.py | POC Details |
| 4 | CVE-2019-9053 Exploit for Python 3 | https://github.com/e-renna/CVE-2019-9053 | POC Details |
| 5 | This is a exploit for CVE-2019-9053 | https://github.com/zmiddle/Simple_CMS_SQLi | POC Details |
| 6 | None | https://github.com/ELIZEUOPAIN/CVE-2019-9053-CMS-Made-Simple-2.2.10---SQL-Injection-Exploit | POC Details |
| 7 | CVE-2019-9053 exploit ported to python3 | https://github.com/pedrojosenavasperez/CVE-2019-9053-Python3 | POC Details |
| 8 | CMS Made Simple < 2.2.10 - SQL Injection | https://github.com/STERN3L/CVE-2019-9053 | POC Details |
| 9 | The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below. | https://github.com/Mahamedm/CVE-2019-9053-Exploit-Python-3 | POC Details |
| 10 | This is the Updated Python3 exploit for CVE-2019-9053 | https://github.com/im-suman-roy/CVE-2019-9053 | POC Details |
| 11 | None | https://github.com/bthnrml/guncel-cve-2019-9053.py | POC Details |
| 12 | Original Exploit Source: https://www.exploit-db.com/exploits/46635 | https://github.com/kahluri/CVE-2019-9053 | POC Details |
| 13 | Python3 version of the Python2 exploit for CVE-2019-9053 | https://github.com/Doc0x1/CVE-2019-9053-Python3 | POC Details |
| 14 | This repository has the sole purpose of rewriting the CVE-2019-9053 script, which in the original publication is written in Python 2.7. I will be using Python 3. | https://github.com/fernandobortotti/CVE-2019-9053 | POC Details |
| 15 | Improved code of Daniele Scanu SQL Injection exploit | https://github.com/byrek/CVE-2019-9053 | POC Details |
| 16 | working exploit for CVE-2019-9053 | https://github.com/davcwikla/CVE-2019-9053-exploit | POC Details |
| 17 | None | https://github.com/BjarneVerschorre/CVE-2019-9053 | POC Details |
| 18 | None | https://github.com/H3xL00m/CVE-2019-9053 | POC Details |
| 19 | None | https://github.com/n3ov4n1sh/CVE-2019-9053 | POC Details |
| 20 | None | https://github.com/c0d3cr4f73r/CVE-2019-9053 | POC Details |
| 21 | None | https://github.com/Jason-Siu/CVE-2019-9053-Exploit-in-Python-3 | POC Details |
| 22 | CVE-2019-9054 exploit added support for python3 + bug fixes | https://github.com/FedericoTorres233/CVE-2019-9053-Fixed | POC Details |
| 23 | This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.10 (CVE-2019-9053). | https://github.com/Dh4nuJ4/SimpleCTF-UpdatedExploit | POC Details |
| 24 | The script has been remastered by Teymur Novruzov to ensure compatibility with Python 3. This tool is intended for educational purposes only. Unauthorized use of this tool on any system or network without permission is illegal. The author is not responsible for any misuse of this tool. | https://github.com/TeymurNovruzov/CVE-2019-9053-python3-remastered | POC Details |
| 25 | None | https://github.com/Sp3c73rSh4d0w/CVE-2019-9053 | POC Details |
| 26 | None | https://github.com/0xwh1pl4sh/CVE-2019-9053 | POC Details |
| 27 | None | https://github.com/N3rdyN3xus/CVE-2019-9053 | POC Details |
| 28 | None | https://github.com/jtoalu/CTF-CVE-2019-9053-GTFOBins | POC Details |
| 29 | None | https://github.com/Azrenom/CMS-Made-Simple-2.2.9-CVE-2019-9053 | POC Details |
| 30 | None | https://github.com/NyxByt3/CVE-2019-9053 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2019-9059 | CMS Made Simple 命令注入漏洞 | |
| CVE-2019-10107 | CMS Made Simple 跨站脚本漏洞 | |
| CVE-2019-10106 | CMS Made Simple 跨站脚本漏洞 | |
| CVE-2019-10105 | CMS Made Simple 跨站脚本漏洞 | |
| CVE-2019-9743 | Phoenix Contact RAD-80211-XD/HP-BUS和Phoenix Contact RAD-80211-XD 命令注入漏洞 | |
| CVE-2019-9744 | 多款Phoenix Contact产品授权问题漏洞 | |
| CVE-2018-15817 | FastStone Image Viewer 缓冲区错误漏洞 | |
| CVE-2018-15816 | FastStone Image Viewer 缓冲区错误漏洞 | |
| CVE-2018-15815 | FastStone Image Viewer 代码问题漏洞 | |
| CVE-2018-15814 | FastStone Image Viewer 缓冲区错误漏洞 | |
| CVE-2018-15813 | FastStone Image Viewer 缓冲区错误漏洞 | |
| CVE-2019-9961 | Wikindx 跨站脚本漏洞 | |
| CVE-2019-10068 | Kentico 代码问题漏洞 | |
| CVE-2019-9061 | CMS Made Simple 代码注入漏洞 | |
| CVE-2019-10061 | node-opencv 操作系统命令注入漏洞 | |
| CVE-2019-9058 | CMS Made Simple 代码注入漏洞 | |
| CVE-2019-9057 | CMS Made Simple 代码注入漏洞 | |
| CVE-2019-9055 | CMS Made Simple 代码问题漏洞 | |
| CVE-2018-19856 | GitLab 路径遍历漏洞 | |
| CVE-2019-7646 | CentOS Web Panel 跨站脚本漏洞 |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet