vendor:
proManager
by:
Kacper (a.k.a Rahim)
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: proManager
Affected Version From: 0.73
Affected Version To: 0.73
Patch Exists: YES
Related CWE: N/A
CPE: a:promanager:promanager:0.73
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
proManager <= 0.73 (Add Admin) SQL Injection Vulnerabilities
A SQL injection vulnerability exists in proManager 0.73, which allows an attacker to inject arbitrary SQL commands via the 'note_id' parameter in the 'note.php' script. This can be exploited to add an admin user with a known username and password.
Mitigation:
Upgrade to the latest version of proManager.