CVE-2021-3018
CRITICAL EXPLOITED NUCLEIipeak Infosystems ibexwebCMS <3.5 - SQL Injection
Title source: llmExploitation Summary
CVE-2021-3018 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including MoeAlBarbari. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a Boolean-based blind SQL injection vulnerability in IPeakCMS 3.5 via the 'id' parameter in the print.php file. The provided payload confirms the vulnerability by leveraging a CASE statement to trigger a true condition.
Description
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.
Exploits (1)
This exploit demonstrates a Boolean-based blind SQL injection vulnerability in IPeakCMS 3.5 via the 'id' parameter in the print.php file. The provided payload confirms the vulnerability by leveraging a CASE statement to trigger a true condition.
Nuclei Templates (1)
body="ipeak" && body="3.5"
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H