CVE-2019-9053 is an unauthenticated blind time-based SQL injection vulnerability in CMS Made Simple 2.2.8. According to the provided content, the flaw is reachable through the News module via a crafted URL and is triggered through the m1_idlist parameter. An attacker can send specially crafted input to this parameter without authentication and leverage time-based inference techniques to execute SQL injection against the backend database. The referenced exploitation extracted application data including a username, password hash, and salt.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
35 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a small standalone exploit repo containing one Python 3 exploit script and a README. The exploit targets CVE-2019-9053 in CMS Made Simple <= 2.2.9 and is a real unauthenticated time-based blind SQL injection exploit, not merely a detector. The script builds requests to the CMS Made Simple News module endpoint /moduleinterface.php?mact=News,m1_,default,0 and injects SQL through the m1_idlist parameter. It uses SELECT sleep(TIME) as a timing oracle and brute-forces values character-by-character from a fixed candidate alphabet. Repository structure is simple: README.md documents the vulnerability, usage, and expected output; exploit.py contains all logic. The script parses command-line options for target URL, optional cracking mode, and optional wordlist. It then sequentially runs dump_salt(), dump_username(), dump_email(), and dump_password(). Each function constructs a LIKE prefix test encoded as hex and measures HTTP response time to determine whether the guessed next character is correct. The salt is extracted from cms_siteprefs where sitepref_name matches sitemask, while username, email, and password hash are extracted from cms_users for user_id=1. If --crack is enabled, crack_password() performs an offline dictionary attack by computing MD5(salt + candidate) for each wordlist entry until it matches the extracted hash. Main exploit capabilities: unauthenticated remote data extraction over HTTP, recovery of admin-related secrets, and optional offline password cracking. There is no shell payload or code execution component; the outcome is credential compromise and potential follow-on account takeover. The code is operational and directly usable, but payload customization is basic and hardcoded around the CMS schema and admin user_id=1.
This repository is a small standalone Python exploit project centered on a single script, mysqli.py, with supporting documentation and dependency/configuration files. The code is a real exploit rather than a detector: it automates unauthenticated time-based blind SQL injection against a vulnerable web application, specifically documented for CVE-2019-9053 affecting CMS Made Simple before 2.2.10. Repository structure is minimal: README.md documents usage and target context, requirements.txt lists Python dependencies, .env.example provides Gmail SMTP variable names for optional reporting, and mysqli.py contains the exploit logic. The script is the clear entry point and implements CLI parsing, signal handling, SQLi payload generation, HTTP request timing, result reporting, optional file output, and optional email delivery. Core exploit behavior: the Injector class defines four extraction modes: database (SELECT database()), tables (enumerate information_schema.tables for the current schema), columns (enumerate information_schema.columns for a chosen table), and exfil (extract arbitrary column data from a chosen table). For each character position, it iterates over a hardcoded charset and sends a POST request containing an injected value like ' OR IF(SUBSTRING((query),pos,1)='c', SLEEP(n), 0)-- -. If the response time exceeds a threshold, the character is considered correct and appended to the result. This repeats until no character matches or the maximum length is reached. The exploit targets web endpoints supplied by the operator via --url and assumes a vulnerable POST parameter, defaulting to username, while also sending a static password field value of 'hello'. It supports multiple comma-separated modes in one run, configurable sleep and delay timing, row offset selection, custom field names, output to a local file, and optional HTML email reporting using Gmail credentials loaded from a .env file. Notable fingerprintable elements include example target paths such as /login.php and /search.php, local files .env and output paths, and MySQL metadata tables information_schema.tables and information_schema.columns. Overall, this is an operational PoC/utility for data extraction via blind SQLi, not a weaponized framework module.
Small standalone Python 3 exploit repository for CVE-2019-9053 against CMS Made Simple <= 2.2.9. The repository contains one primary code file (exploit_ctf.py), a README explaining the vulnerability and lab usage, a requirements file, and an example wordlist. The exploit is not part of a larger framework. The script performs unauthenticated time-based blind SQL injection against the CMS endpoint /moduleinterface.php?mact=News,m1_,default,0 by appending crafted SQL to the m1_idlist parameter. It measures HTTP response time to determine whether a guessed prefix is correct, using SQL sleep(1) as the side channel. The extraction logic is implemented in dump_value(), which iteratively tests characters from a charset and reconstructs values character by character. The exploit specifically targets cms_siteprefs to recover the application salt and cms_users to recover the username, email, and password hash for user_id 1. This CTF-modified version includes hardcoded known prefixes (salt, username, email, hash) to speed up extraction in lab scenarios, making it more operational than a bare PoC but still relatively simple. After data extraction, the script can optionally perform offline password cracking using a supplied wordlist. It computes md5(salt + candidate) for each candidate and compares it to the extracted hash. This means the exploit’s end result can be full credential recovery, not just information disclosure. Repository structure is straightforward: exploit_ctf.py is the only executable component; requirements.txt lists requests and termcolor; wordlist-example.txt is a sample cracking dictionary; README.md documents usage, expected output, and the educational/CTF modifications.
Repository is a small standalone exploit PoC consisting of one Python 2 script (46635.py) and a README. The script targets CVE-2019-9053, an unauthenticated time-based blind SQL injection in CMS Made Simple <= 2.2.9. It builds a target URL by appending /moduleinterface.php?mact=News,m1_,default,0 to a user-supplied base URL and injects SQL through the m1_idlist parameter. The exploit uses repeated HTTP GET requests and response timing to recover data one character at a time from the backend database. It contains four main extraction routines: dump_salt() reads the sitemask value from cms_siteprefs, dump_username() reads the username from cms_users for user_id 1, dump_email() reads the email for user_id 1, and dump_password() reads the password hash for user_id 1. Each routine iterates over a hardcoded candidate character set and tests prefixes using SQL LIKE with hex-encoded strings plus a trailing wildcard, triggering SLEEP(TIME) when the guess is correct. After data extraction, the optional crack_password() function performs offline dictionary cracking against the recovered MD5(salt + password) hash using a user-provided wordlist. This makes the exploit more than a pure disclosure PoC: it can directly recover usable administrator credentials if the password is weak and present in the wordlist. There are no hardcoded external IPs or domains in the exploit logic; the only network target is the operator-supplied CMS URL. The code is operational but basic: payloads are hardcoded, the timing threshold is fixed via the TIME variable, and it assumes the interesting account is user_id 1. Overall purpose is credential extraction from vulnerable CMS Made Simple instances, with optional password recovery.
This repository is a small standalone exploit repo containing one Python exploit script (Glowfish.py) and a brief README. The script targets CMS Made Simple CVE-2019-9053, an unauthenticated time-based blind SQL injection in the News module interface. It is not a framework module. Glowfish.py accepts a base target URL, constructs requests to /moduleinterface.php?mact=News,m1_,default,0, and injects SQL through the m1_idlist parameter. The exploit uses repeated HTTP GET requests and response timing to brute-force values character by character from a fixed dictionary. It contains four main extraction routines: dump_salt() retrieves the application salt from cms_siteprefs, dump_username() retrieves the username from cms_users for user_id 1, dump_email() retrieves the email for user_id 1, and dump_password() retrieves the password hash for user_id 1. After extraction, crack_password() can optionally perform offline cracking by comparing hashlib.md5(salt + candidate).hexdigest() against the recovered hash using a user-provided wordlist. The exploit’s main capability is credential harvesting rather than code execution: it leaks administrator account metadata and password material from a vulnerable CMS instance without authentication. The script is operational but basic: payloads are hardcoded, extraction is sequential, and success depends on tuning the TIME delay for the target environment. The README is minimal and slightly inconsistent with the script comments, mentioning CMS Made Simple < 2.2.10 while the script header states <= 2.2.9, but both clearly refer to the same SQL injection issue.
Repository contains a single Python exploit script (46635.py) and a README walkthrough. The exploit targets CMS Made Simple <= 2.2.9, specifically CVE-2019-9053, an unauthenticated time-based blind SQL injection in the News module endpoint. The script accepts a base URL and optional wordlist/cracking flag, builds requests to <base>/moduleinterface.php?mact=News,m1_,default,0, and injects SQL through the m1_idlist GET parameter. It iteratively brute-forces field values one character at a time by appending candidate characters, issuing HTTP GET requests, and checking whether response time exceeds the configured TIME threshold due to SQL sleep(). The script extracts the CMS salt from cms_siteprefs and the username, email, and password hash for cms_users.user_id=1. If the --crack option is supplied, it performs offline dictionary cracking against the recovered salted MD5 hash using hashlib.md5(salt + candidate). The code is a functional exploit rather than a detector, but it is relatively basic and hardcoded: it assumes specific table names, field names, and admin user_id 1. README.md is contextual documentation for a TryHackMe/Simple CTF walkthrough and mentions broader attack-chain steps, but those actions are not implemented in the repository code.
This repository is a small exploit repo containing one Python exploit script (46635.py) and one README walkthrough. The exploit is a real, standalone proof-of-concept/operational script for CVE-2019-9053, an unauthenticated time-based blind SQL injection affecting CMS Made Simple <= 2.2.9. It targets the News module endpoint by building requests to /moduleinterface.php?mact=News,m1_,default,0 and injecting SQL through the m1_idlist GET parameter. The script uses requests.Session() and repeatedly measures response timing to infer whether guessed prefixes are correct. It enumerates values character-by-character from a fixed dictionary using SQL LIKE prefix matching and SELECT SLEEP(TIME). Specifically, it extracts the password salt from cms_siteprefs (sitepref_name sitemask), then extracts the first user's username, email, and password hash from cms_users where user_id = 1. After data extraction, it can optionally perform offline cracking of the recovered hash using a user-supplied wordlist and MD5(salt + password_candidate). Repository structure is minimal: the Python file is the only code and clear entry point; README.md is contextual documentation describing a TryHackMe/Simple CTF walkthrough and broader attack chain, but the actual repository code only implements the SQLi data extraction and optional hash cracking. There is no post-exploitation shell, privilege escalation, persistence, or framework integration in the code itself.
This repository is a small standalone Python 3 exploit for CVE-2019-9053 affecting CMS Made Simple <= 2.2.9. It contains only two files: a minimal README and a single executable script, exploit.py, which is the clear entry point and contains all exploit logic. The exploit targets an unauthenticated SQL injection in the CMS Made Simple module interface endpoint. It builds requests to the target-supplied base URL plus /moduleinterface.php?mact=News,m1_,default,0 and injects SQL through the m1_idlist parameter. The technique is time-based blind SQLi: for each candidate character in a predefined dictionary, the script sends a request containing a conditional sleep(TIME) query and infers correct characters by measuring response delay. The script is structured as a sequence of extraction functions: - dump_salt(): queries cms_siteprefs to recover the site salt (named sitemask in the payload). - dump_username(): queries cms_users for the username of user_id 1. - dump_email(): queries cms_users for the email of user_id 1. - dump_password(): queries cms_users for the password hash of user_id 1. - crack_password(): optional offline cracking routine that reads a local wordlist and compares MD5(salt + candidate) against the extracted hash. Operationally, this is more than a detector: it actively extracts sensitive data from the backend database and can recover plaintext credentials if the hash is crackable with the provided wordlist. It does not deliver code execution or a shell; its main capability is credential theft via blind SQL injection followed by optional offline password cracking. Notable implementation details include use of requests.Session() for repeated HTTP requests, optparse-based CLI arguments (-u, -w, -c), a hardcoded candidate character dictionary, and a configurable TIME threshold defaulting to 1 second. The exploit assumes the first administrative account is user_id 1 and that the target database schema uses cms_siteprefs and cms_users with the expected columns.
This repository is a small, single-purpose exploit for CVE-2019-9053 affecting CMS Made Simple <= 2.2.9. It contains only two files: a minimal README and one Python script, mainn.py, which is the full exploit implementation. The script is not part of a larger exploitation framework. The exploit targets an unauthenticated SQL injection in the CMS Made Simple News module endpoint. It builds requests to the target path /moduleinterface.php?mact=News,m1_,default,0 and injects SQL through the m1_idlist parameter. The technique is blind and time-based: for each guessed character, the script issues an HTTP GET containing a payload with SQL sleep(TIME), then measures response delay to determine whether the guessed prefix is correct. Functionally, the script enumerates sensitive values character by character from the backend database. dump_salt() extracts the application salt from cms_siteprefs by matching the site preference name 'sitemask'. dump_username(), dump_email(), and dump_password() extract the username, email address, and password hash from cms_users for user_id 1, which is likely the primary administrator account. After recovering the hash, the optional crack_password() routine performs offline dictionary cracking using a user-supplied wordlist and MD5(salt + password_candidate). The repository structure is straightforward: README.md only identifies the CVE, while mainn.py handles argument parsing, HTTP session management, timing-based inference, terminal output, and optional hash cracking. There is no post-exploitation shell, file write, or remote code execution capability; the main purpose is credential extraction and possible password recovery.
This repository is a small standalone exploit project with 2 files: a README describing modernization/fixes and a single Python entry point, exploit.py. The code targets CVE-2019-9053, an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9. It is not part of a larger exploitation framework. The exploit builds a vulnerable URL by appending /moduleinterface.php?mact=News,m1_,default,0 to a user-supplied base URL, then injects SQL through the m1_idlist parameter. It uses time-based blind SQL injection with sleep() to enumerate one character at a time from backend data. Specifically, it extracts the CMS salt from cms_siteprefs (filtering on the sitemask preference), then extracts username, email, and password hash from cms_users for user_id 1. The extraction logic iterates over a hardcoded candidate character set and treats delayed responses as a positive match. A secondary capability is offline password cracking: if the operator supplies a wordlist and enables --crack, the script computes MD5(salt + candidate) for each word and compares it to the extracted password hash. This makes the exploit more than a pure PoC, since it can directly recover usable credentials when the password is weak and present in the wordlist. Repository structure is simple: README.md documents Python 3 migration and quality improvements; exploit.py contains argument parsing, HTTP session handling, extraction routines, and optional cracking logic. The main entry point is main(), which parses --url, --wordlist, --crack, and --time arguments and runs the CMSMSExploit class. Overall, this is an operational standalone web exploit for credential extraction and optional password recovery against vulnerable CMS Made Simple instances.
Repository contains a single Python 3 exploit script and a README. The script targets CMS Made Simple <= 2.2.9 (CVE-2019-9053) using an unauthenticated time-based blind SQL injection against the News module endpoint /moduleinterface.php?mact=News,m1_,default,0, injecting into the m1_idlist parameter. It iteratively brute-forces character-by-character values using a fixed dictionary of alphanumerics and symbols, measuring response time to detect when a guessed prefix is correct (via SELECT SLEEP(TIME)). It extracts: (1) the password salt from cms_siteprefs where sitepref_name='sitemask', (2) admin username and email from cms_users where user_id=1, and (3) the admin password hash from cms_users where user_id=1. If invoked with --crack and a -w wordlist, it performs offline dictionary cracking by computing md5(salt + candidate) and comparing to the extracted hash. No reverse shell or code execution is implemented; the primary capability is credential material extraction and optional password recovery.
Repository contains a single Python proof-of-concept exploit script for CVE-2019-9053 (CMS Made Simple SQL injection in the News module). Structure: README.md (minimal note) and script.py (main exploit). The script takes a base URL (-u/--url) and constructs a target endpoint: <base>/moduleinterface.php?mact=News,m1_,default,0, then performs time-based blind SQL injection by appending &m1_idlist=<payload>. It iteratively brute-forces characters (up to 32) from a defined dictionary by testing prefixes with a LIKE 0x<hex> pattern and measuring whether the server response time exceeds TIME=1 second due to a triggered sleep(1). It first extracts the CMS salt (from cms_siteprefs where sitepref_name like 'sitemask'), then dumps username, email, and password hash from cms_users for user_id=1. It prints a summary and suggests using hashcat/john; a wordlist cracking option is present but the cracking logic is not implemented.
Repository contains a single Python exploit script (exploit.py) and a README. The script targets CVE-2019-9053 (unauthenticated time-based blind SQL injection) in CMS Made Simple <= 2.2.9 by sending repeated HTTP GET requests to the News module interface endpoint: <base_url>/moduleinterface.php?mact=News,m1_,default,0 with a crafted m1_idlist parameter. Core capability is data extraction via timing: it brute-forces character-by-character prefixes using a fixed dictionary and checks whether the server delays by TIME=1 second (SELECT SLEEP(1)) to confirm a correct prefix. It extracts (1) the password salt from cms_siteprefs where sitepref_name like 'sitemask', and from cms_users (user_id=1) it extracts (2) username, (3) email, and (4) password hash. If --crack is enabled and a wordlist is provided, it performs offline cracking by computing MD5(salt + candidate) and comparing to the extracted hash. No post-exploitation remote code execution is implemented; the exploit focuses on credential material extraction and optional offline password recovery. The script uses Python requests.Session for HTTP, optparse for CLI args, and prints progress by clearing the terminal.
Repository contains a single Python3 exploit script (cmsms-sqli.py), a README, and an MIT LICENSE. The script is an operational PoC/exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9) implementing time-based blind SQL injection against the News module endpoint at moduleinterface.php?mact=News,m1_,default,0. It takes one argument (base URL), constructs the target URL by appending /moduleinterface.php?mact=News,m1_,default,0, then iteratively brute-forces characters using response-time delays (sleep(TIME)) to extract three values: the site salt (cms_siteprefs.sitemask), the admin username (cms_users.username where user_id=1), and the admin password MD5 hash (cms_users.password where user_id=1). Output includes hashcat-ready formatting (md5:salt) and next-step guidance (crack -> login admin -> upload shell). No external dependencies beyond requests; configurable TIME and timeout values are hardcoded near the top.
This repository contains a working exploit for CVE-2019-9053, a time-based blind SQL injection vulnerability in CMS Made Simple versions <= 2.2.9. The main file, 'exploit.py', is a Python script that automates the exploitation process. It targets the 'moduleinterface.php' endpoint with a crafted 'm1_idlist' parameter to perform SQL injection and extract sensitive information such as the admin's username, email, password hash, and salt. The script can also attempt to crack the admin password using a supplied wordlist. The exploit is unauthenticated and relies on network access to the vulnerable CMS instance. The repository also includes a README with usage instructions and a LICENSE file. The exploit is operational and provides real extraction and cracking capabilities, not just detection.
This repository contains a Python3 exploit script (exploit_python3.py) and a README.md. The exploit targets CMS Made Simple (CMSMS) versions 2.2.9 and below, specifically exploiting CVE-2019-9053, an unauthenticated time-based blind SQL injection vulnerability. The script automates extraction of sensitive information (salt, username, email, password hash) from the CMS database by sending crafted requests to the vulnerable 'moduleinterface.php?mact=News,m1_,default,0' endpoint, using the 'm1_idlist' parameter to inject SQL payloads that leverage the 'sleep' function for timing-based inference. Optionally, the script can attempt to crack the admin password using a supplied wordlist. The repository is well-structured, with clear usage instructions and a focus on educational and authorized penetration testing. No hardcoded IPs or domains are present; the target URL is supplied by the user at runtime.
This repository contains a single Python script, 'sqli.py', which exploits a time-based blind SQL injection vulnerability (CVE-2019-9053) in CMS Made Simple versions 2.2.9 and earlier. The script targets the 'moduleinterface.php' endpoint, specifically the 'm1_idlist' parameter, to extract sensitive information from the database, including the admin username, email, password hash, and salt. The exploit is unauthenticated and requires only the base URL of the target CMS installation. Optionally, the script can attempt to crack the admin password hash using a supplied wordlist. The code is operational and demonstrates a full attack chain from extraction to optional password cracking. The repository is well-structured for its purpose, containing only the exploit script, and is written in Python.
This repository contains a Python 3 exploit script (cms_exploit.py) and a README.md. The exploit targets an unauthenticated time-based blind SQL injection vulnerability (CVE-2019-9053) in CMS Made Simple versions prior to 2.2.10. The script automates the extraction of sensitive admin information (salt, username, email, password hash) by sending crafted GET requests to the vulnerable endpoint '/moduleinterface.php?mact=News,m1_,default,0' with a manipulated 'm1_idlist' parameter. Optionally, it can attempt to crack the extracted password hash using a user-supplied wordlist. The README provides detailed usage instructions, requirements, and background on the vulnerability. The exploit is operational, providing real extraction and optional cracking functionality, and is intended for educational and authorized testing purposes only.
This repository contains a Python exploit script (exploit_2019.py) targeting CVE-2019-9053, a time-based blind SQL injection vulnerability in CMS Made Simple versions <= 2.2.9. The exploit automates the extraction of sensitive information (admin username, email, password hash, and salt) from the target CMS instance by sending crafted requests to the 'moduleinterface.php' endpoint, specifically abusing the 'm1_idlist' parameter. The script can also attempt to crack the admin password using a supplied wordlist. The repository includes a README with usage instructions, a LICENSE file, and an empty requirements file. The exploit is operational, requiring only the target URL and, optionally, a wordlist for password cracking. No authentication is needed, and the attack is performed over the network against a web-accessible CMS Made Simple instance.
This repository contains a Python 3 exploit script (cmsms_sqli_py3.py) and a README.md file. The exploit targets CMS Made Simple versions 2.2.9 and below, leveraging an unauthenticated time-based blind SQL injection vulnerability in the 'moduleinterface.php' endpoint with the News module. The script automates extraction of the password salt, admin username, admin email, and admin password hash from the database by sending crafted requests and measuring response delays. Optionally, it can attempt to crack the extracted password hash using a user-supplied wordlist. The exploit is fully automated, requires only the target URL, and optionally a wordlist for password cracking. The README provides clear usage instructions, requirements, and an overview of the attack. No hardcoded credentials or static payloads are present; the exploit dynamically extracts data from the target. The repository is operational and suitable for penetration testing or educational purposes.
This repository contains a Python exploit script (46635.py) and a brief README for CVE-2019-9053, a time-based blind SQL injection vulnerability in CMS Made Simple versions <= 2.2.9. The exploit is unauthenticated and targets the '/moduleinterface.php?mact=News,m1_,default,0' endpoint of a CMS Made Simple installation. The script automates the extraction of the admin's salt, username, email, and password hash by sending crafted SQL injection payloads and measuring response times. If a wordlist is provided, it can attempt to crack the admin password using the extracted salt and hash. The exploit is operational and requires only the target URL and, optionally, a wordlist for password cracking. The repository is straightforward, with the main exploit logic contained in a single Python file.
This repository contains a Python 3 port of an exploit for CVE-2019-9053, targeting CMS Made Simple versions 2.2.9 and below. The main exploit script, 'cve_2019_9053_python3.py', performs an unauthenticated time-based blind SQL injection attack against the News module's 'm1_idlist' parameter. By iteratively sending crafted requests and measuring response times, the script extracts sensitive information from the database, including the admin's salt, username, email, and password hash. If a wordlist is provided, the script can attempt to crack the admin password using the extracted salt and hash. The exploit requires only the base URL of the target CMS instance and does not require authentication. The repository is structured with a single exploit script and a README detailing the porting process and usage. The attack vector is network-based, exploiting a web application endpoint. The script is operational and ready to use in modern environments.
This repository contains a single Python exploit script targeting CVE-2019-9053, an unauthenticated blind time-based SQL injection vulnerability in CMS Made Simple versions 2.2.9 and below. The script takes a base URL to a CMS Made Simple instance and exploits the 'm1_idlist' parameter of the News module's 'moduleinterface.php' endpoint to extract sensitive information from the database, including the admin username, email, password hash, and the site salt. The script can optionally attempt to crack the admin password using a supplied wordlist. The code is operational and automates the extraction process, providing a clear output of the compromised credentials. The repository is well-structured, with a single entry-point script and clear argument parsing for user interaction. No hardcoded endpoints or credentials are present; the target URL is supplied at runtime.
This repository contains a Python 3 port of an exploit for CVE-2019-9053, targeting CMS Made Simple (CMSMS) versions prior to 2.2.10. The main exploit logic resides in 'exploit.py', which implements a time-based blind SQL injection attack against the News module interface of CMSMS. The exploit automates the extraction of sensitive information from the CMS database, including the CMS salt, admin username, admin email, and admin password hash. If a wordlist is provided, the script can attempt to crack the admin password hash. The exploit requires the attacker to specify the base URL of the target CMS instance and optionally a wordlist for password cracking. The repository is structured with standard Python project files, including a requirements.txt for dependencies, a README.md with usage instructions, and a minimal __init__.py. The attack vector is network-based, exploiting a vulnerable HTTP endpoint. No hardcoded IPs or domains are present; the target is specified at runtime.
This repository contains a Python exploit script (exploit.py) targeting CVE-2019-9053, an unauthenticated time-based blind SQL injection vulnerability in CMS Made Simple versions 2.2.9 and below. The exploit works by sending crafted requests to the /moduleinterface.php endpoint with a vulnerable m1_idlist parameter, leveraging time delays to extract sensitive admin information (salt, username, email, password hash) from the database. The script optionally supports password cracking using a supplied wordlist. The repository includes a README with detailed usage instructions and a LICENSE file. The exploit is operational, providing real credential extraction and optional password cracking, and is intended for use by security professionals on authorized systems.
This repository contains a Python exploit script (exploit.py) targeting an unauthenticated time-based blind SQL injection vulnerability in CMS Made Simple versions 2.2.9 and earlier (CVE-2019-9053). The exploit works by sending specially crafted requests to the 'moduleinterface.php' endpoint, specifically manipulating the 'm1_idlist' parameter to extract the admin username, email, password hash, and salt from the database. The script automates the extraction process character by character, using time delays to infer correct values. Optionally, if a wordlist is provided, the script can attempt to crack the extracted password hash using the retrieved salt. The repository also includes a README.md with usage instructions and a LICENSE file. The exploit is operational and does not require authentication, making it a significant risk for unpatched CMS Made Simple installations.
This repository contains a Python exploit script (CmsSQLi.py) targeting an unauthenticated time-based blind SQL injection vulnerability (CVE-2019-9053) in CMS Made Simple versions <= 2.2.9. The exploit automates the extraction of sensitive admin information (username, email, password hash, and salt) from the database by exploiting the 'm1_idlist' parameter in the News module's 'moduleinterface.php' endpoint. The script can also attempt to crack the admin password using a supplied wordlist. The repository consists of the main exploit script and a brief README. The exploit is operational and requires the attacker to provide the base URL of the target CMS instance. No hardcoded endpoints or credentials are present; the script is interactive and requires user input for the target URL and optional wordlist.
This repository contains a Python 3 exploit script (cve.py) targeting CVE-2019-9053, an unauthenticated time-based blind SQL injection vulnerability in CMS Made Simple versions <= 2.2.9. The exploit automates the extraction of the admin password salt, username, email, and password hash by sending crafted requests to the vulnerable 'moduleinterface.php' endpoint. If a wordlist is provided, the script attempts to crack the admin password using the extracted salt and hash. The repository also includes a sample wordlist (best110.txt) and a README.md with usage instructions and example output. The exploit requires only the base URL of the target CMS instance and does not require authentication, making it a potent tool for extracting sensitive credentials from vulnerable installations.
This repository contains a Python 3 exploit for CVE-2019-9053, targeting CMS Made Simple versions 2.2.9 and below. The exploit leverages a time-based blind SQL injection vulnerability in the 'moduleinterface.php' endpoint, specifically via the 'm1_idlist' parameter. The script automates the extraction of the admin salt, username, email, and password hash from the database. If a wordlist is provided, it can also attempt to crack the admin password. The exploit is unauthenticated and requires only the base URL of the target CMS instance. The repository consists of a single exploit script ('exploit.py') and a README file with usage instructions and background information. The exploit is operational and provides real credential extraction and optional password cracking functionality.
This repository contains a Python 3 exploit script (updated_46635.py) targeting an unauthenticated time-based blind SQL injection vulnerability (CVE-2019-9053) in CMS Made Simple versions <= 2.2.10. The exploit automates the extraction of sensitive admin information (salt, username, email, password hash) from the CMS database by sending crafted GET requests to the vulnerable 'moduleinterface.php' endpoint. The script includes improved error handling, retry logic, and optional password cracking using a supplied wordlist. The repository consists of the main exploit script and a detailed README explaining usage, requirements, and the vulnerability. The attack vector is network-based, requiring only HTTP access to the target CMS instance. No hardcoded IPs or domains are present; the user supplies the target URL as a parameter.
This repository contains a Python 3 exploit script targeting CVE-2019-9053, a time-based blind SQL injection vulnerability in CMS Made Simple (CMSMS) version 2.2.9 and below. The main file, 'csm_made_simple_injection.py', is a standalone exploit that automates the extraction of sensitive information (salt, username, email, and password hash) from the CMSMS database by sending crafted SQL injection payloads to the '/moduleinterface.php?mact=News,m1_,default,0' endpoint. The script uses timing responses to infer data, character by character. Optionally, it can attempt to crack the extracted password hash using a supplied wordlist and MD5 hashing. The exploit does not require authentication and is operational against vulnerable CMSMS instances accessible over the network. The repository also includes a README.md with detailed usage instructions and a 'requirement.txt' listing Python dependencies. No hardcoded IPs or domains are present; the target is specified by the user at runtime.
This repository contains a Python 3 script ('remastered_exploit.py') that exploits a time-based blind SQL injection vulnerability (CVE-2019-9053) in CMS Made Simple. The exploit targets the '/moduleinterface.php?mact=News,m1_,default,0' endpoint, appending a crafted 'm1_idlist' parameter to perform the injection. The script automates the extraction of sensitive information from the CMS database, including the password salt, username, email, and hashed password of a user (typically the admin). Optionally, it can attempt to crack the password using a wordlist and the extracted salt. The exploit requires the attacker to specify the base URL of the target CMS instance and optionally enable password cracking. The repository consists of the main exploit script and a README file with usage instructions and details about the vulnerability. The exploit is operational and provides real data extraction and optional password cracking capabilities.
This repository contains a Python 3 exploit script (exploit-cve-2019-9053.py) targeting CVE-2019-9053, a time-based blind SQL injection vulnerability in CMS Made Simple version 2.2.8. The exploit works by sending specially crafted HTTP GET requests to the '/moduleinterface.php?mact=News,m1_,default,0' endpoint, manipulating the 'm1_idlist' parameter to perform time-based inference of sensitive database fields. The script automates extraction of the admin's username, email, password hash, and salt. If a wordlist is provided, it can attempt to crack the admin password using the extracted salt and MD5 hashing. The repository also includes a README.md with usage instructions and a reference to the original Exploit-DB entry. The exploit is operational and requires the attacker to specify the target URL and, optionally, a wordlist for password cracking.
This repository contains a Python 3 exploit script (exploit.py) and a README.md for CVE-2019-9053, a time-based blind SQL injection vulnerability in CMS Made Simple versions 2.2.9 and earlier. The exploit is unauthenticated and targets the 'moduleinterface.php' endpoint with a crafted 'm1_idlist' parameter to extract the administrator's salt, username, email, and hashed password from the database. The script can optionally attempt to crack the password using a supplied wordlist. The repository is structured simply, with the main exploit logic in 'exploit.py' and detailed usage instructions in the README. The attack vector is network-based, requiring only HTTP access to the vulnerable CMS instance. No fake or detection-only code is present; this is a functional exploit with operational maturity.
This repository contains a Python 3 exploit script (46635.py) targeting CVE-2019-9053, a time-based blind SQL injection vulnerability in CMS Made Simple versions up to 2.2.9. The exploit automates extraction of sensitive admin credentials (salt, username, email, password hash) from the database by sending crafted requests to the vulnerable endpoint (/moduleinterface.php?mact=News,m1_,default,0) and measuring response times to infer data. Optionally, it can attempt to crack the admin password using a supplied wordlist. The script is operational and requires the attacker to specify the target URL and, if desired, a wordlist for password cracking. The repository also includes a README.md describing the exploit and its Python 3 refactor. No hardcoded IPs or domains are present; the target is specified at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.