vendor:
AskMe Pro
by:
CoBRa_21
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: AskMe Pro
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
AlstraSoft AskMe Pro ( profile.php?id ) SQL Injection Vulnerability
A vulnerability exists in AlstraSoft AskMe Pro, which allows an attacker to inject malicious SQL commands into the profile.php?id parameter. This can be exploited to gain access to the database and potentially disclose sensitive information.
Mitigation:
Input validation should be used to prevent SQL injection attacks. Additionally, the application should be configured to use the least privileged account with access to the database.