vendor:
Top Sites Script
by:
3spi0n
5,5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: Top Sites Script
Affected Version From: 2.2.1
Affected Version To: 2.2.1
Patch Exists: YES
Related CWE: CVE-2018-19072
CPE: a:scriptsgenie:top_sites_script:2.2.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2018
Top Sites Script, SQL Injection Vulnerabilities
Top Sites Script is prone to a SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this vulnerability to manipulate SQL queries by injecting arbitrary SQL code. This may allow the attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Mitigation:
The vendor has released a patch to address this vulnerability.