dejimason
Smart Wallet Architect
2
MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1
400 XP
data:image/s3,"s3://crabby-images/96114/96114d475893e20200f7a6753a15bf28dd4d7d4b" alt="CVE-2020-5515.png"
Hey folks, today we will show you (PoC) of “Gila CMS 1.11.8 – ‘query’ SQL Injection” vulnerability. The get parameter “query” is vulnerable, hence we will use the SQL injection tool
data:image/s3,"s3://crabby-images/51fde/51fde71731ffd8111999267a0429dcfc7b00dbd7" alt="Syringe :syringe: 💉"
About the Vulnerability
- Exploit Author: Carlos Ramírez L. (BillyV4)
- Vendor Homepage: https://gilacms.com/
- Version: Gila 1.11.8
- CVE : CVE-2020-5515
Vulnerability Setup
wget https://github.com/GilaCMS/gila/archive/1.11.8.zip
unzip gila-1.11.8.zip
mkdir gila /var/www/html/
cp -R gila-1.11.8/* /var/www/html/gila/
cp gila-1.11.8/.htaccess /var/www/html/gila/
chown -R www-data:www-data gila/123456wget https://github.com/GilaCMS/gila/archive/1.11.8.zipunzip gila-1.11.8.zipmkdir gila/var/www/html/cp-Rgila-1.11.8/*/var/www/html/gila/cp gila-1.11.8/.htaccess/var/www/html/gila/chown-Rwww-data:www-data gila/
data:image/s3,"s3://crabby-images/d9941/d9941eec90ba26d501bfe845f30f78fe0154c940" alt="1-14.png"
Full Proof of Concept
Step -1
data:image/s3,"s3://crabby-images/77c1d/77c1d246eea08905c11592677205686d1ca60064" alt="burp.png"
Step -2
Usage
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
data:image/s3,"s3://crabby-images/54dca/54dca458c1b473a12a600bbb9470f07540f08e13" alt="sqlcommand.png"
Step -3
data:image/s3,"s3://crabby-images/aa7d0/aa7d0f75c930a60206518f2258d7e944c7f87c9f" alt="result.png"