vendor:
Clone Version
by:
Easy Laster
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Clone Version
Affected Version From: 3.0 (Special)
Affected Version To: 3.0 (Special)
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2010
Alibaba Clone Version <= 3.0 (Special) SQL Injection Vulnerability Exploit
This exploit is used to gain access to the username and password of users in the Alibaba Clone Version 3.0 (Special) script. It is done by sending a malicious HTTP request to the offers_buy.php page with an id parameter containing a SQL injection payload. This payload will cause the database to return the username and password of all users in the database.
Mitigation:
Input validation should be used to prevent SQL injection attacks. All user input should be validated and filtered before being used in a SQL query.