724CMS 5.01 Multiple SQL Injection Security Vulnerabilities

Posted by Jing Wang on Mar 16

*724CMS 5.01 Multiple SQL Injection Security Vulnerabilities*

Exploit Title: 724CMS Multiple SQL Injection Security Vulnerabilities
Vendor: 724CMS
Product: 724CMS
Vulnerable Versions: 3.01 4.01 4.59 5.01
Tested Version: 5.01
Advisory Publication: March 14, 2015
Latest Update: March 14, 2015
Vulnerability Type: Improper Neutralization of Special Elements used in an
SQL Command (‘SQL Injection’) [CWE-89]
CVE Reference: *
Impact…