CVE-2014-1459
doorGets CMS <= 5.2 - Authenticated SQL Injection via _position_down_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-1459. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This PoC demonstrates a SQL Injection vulnerability in doorGets CMS via the '_position_down_id' parameter, exploitable via CSRF. It uses DNS exfiltration to extract database information, such as the MySQL version, by forcing a DNS lookup to an attacker-controlled domain.
Description
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the _position_down_id parameter. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.
Exploits (1)
This PoC demonstrates a SQL Injection vulnerability in doorGets CMS via the '_position_down_id' parameter, exploitable via CSRF. It uses DNS exfiltration to extract database information, such as the MySQL version, by forcing a DNS lookup to an attacker-controlled domain.