vendor:
Mayasan Portal
by:
CoBRa_21
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Mayasan Portal
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: N/A
Related CWE: N/A
CPE: a:mayasan:mayasan_portal:2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Mayasan Portal v2.0 (haberdetay.asp?id) SQL Injection Vulnerability
A vulnerability exists in Mayasan Portal v2.0, which allows an attacker to inject arbitrary SQL commands into the 'haberdetay.asp?id' parameter. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Mitigation:
Input validation should be used to prevent SQL injection attacks.