vendor:
Tiny Tiny RSS
by:
Kacper Szurek
7,5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Tiny Tiny RSS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Tiny Tiny RSS Blind SQL Injection
$item_id inside process_category_order() is not properly escaped. We control this value using $_POST['payload']. Login as regular user and submit a form with a payload containing a malicious SQL query.
Mitigation:
Update to version a5556c2471973e292dce615fe0c77fdbbc54405b