microASP Portal+ CMS SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability has been identified in microASP Portal+ CMS. This issue allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the 'explode_tree' parameter of 'pagina.phtml'. Exploitation of this vulnerability enables attackers to extract sensitive database information, such as the current database name, using crafted SQL injection payloads that leverage the 'extractvalue' and 'concat' functions.
Impact
Exploitation of this vulnerability allows for arbitrary SQL execution, which could lead to unauthorized data access or manipulation.
Reproduction
To reproduce this vulnerability, send a request to 'pagina.phtml' with the 'explode_tree' parameter. Inject a SQL payload that uses the 'extractvalue' and 'concat' functions to extract database information. The current database name can be retrieved by concatenating it with a custom string, such as 'sx0u:'.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
