vendor:
Uiga Church Portal
by:
Easy Laster
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Uiga Church Portal
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Uiga Church Portal index.php SQL Injection
The vulnerability exists in the 'index.php' script of Uiga Church Portal, which allows an attacker to inject arbitrary SQL commands via the 'id' parameter in the 'view=read' module.
Mitigation:
Input validation should be used to prevent SQL injection attacks.