CVE-2021-3018

CRITICAL EXPLOITED NUCLEI

ipeak Infosystems ibexwebCMS <3.5 - SQL Injection

Title source: llm

Description

ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.

Exploits (1)

exploitdb WORKING POC
by MoeAlBarbari · textwebappsmultiple
https://www.exploit-db.com/exploits/49372

Nuclei Templates (1)

IPeakCMS 3.5 - SQL Injection
CRITICALby theamanrawat
FOFA: body="ipeak" && body="3.5"

Scores

CVSS v3 9.8
EPSS 0.7933
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-07-25
CWE
CWE-89
Status published
Products (1)
ipeak/ipeakcms 3.5
Published Jan 05, 2021
Tracked Since Feb 18, 2026