vendor:
WhiteBoard
by:
Salvatore Fresta aka Drosophila
7,5
CVSS
HIGH
Multiple Blind SQL Injection
89
CWE
Product Name: WhiteBoard
Affected Version From: 0.1.30
Affected Version To: 0.1.30
Patch Exists: NO
Related CWE: N/A
CPE: a:sarosoftware:whiteboard
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
WhiteBoard 0.1.30 Multiple Blind SQL Injection Vulnerabilities
Some parameters in controlpanel.php are not properly sanitised before being used in SQL queries, which can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Successful exploitation requires that 'magic_quotes_gpc' is disabled.
Mitigation:
No fix.