IdeaCMS <= 1.7 - SQL Injection
Short Info
Level
Critical
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
22 days 14 hours
Scan only one
Domain, Subdomain, IPv4
Toolbox
-
IdeaCMS up to 1.7 is vulnerable to SQL injection via the field parameter in article and product query interfaces. This template uses a time-based payload to safely detect the vulnerability.
References: