The exploit demonstrates a SQL injection vulnerability in Mambo CMS 4.6.5 via the 'zorder' parameter in the administrator/index2.php URL. The PoC includes a crafted URL that manipulates SQL queries to disclose arbitrary data from the database.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:Mambo CMS 4.6.5 and lower
No auth needed
Prerequisites:Access to the target Mambo CMS administrator interface