vendor:
Free Reality
by:
Vulnerability Laboratory Researcher Team
7,5
CVSS
CRITICAL
SQL Injection & Persistent Input Validation
89 (SQL Injection) & 79 (Cross-site Scripting)
CWE
Product Name: Free Reality
Affected Version From: Free Reality v3.1-0.6
Affected Version To: Free Reality v3.1-0.6
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Free Reality v3.1-0.6 – Multiple Web Vulnerabilities
A remote SQL Injection vulnerability is detected in the Free Reality v3.1-0.6 web application. The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms. Multiple persistent input validation vulnerabilities are detected in the Free Reality v3.1-0.6 web application. The bugs allow remote attackers to implement/inject malicious script code on the application side (persistent).
Mitigation:
Input validation, parameterized queries, and proper authentication and authorization.