header-logo
Suggest Exploit
vendor:
MLMAuction
by:
3spi0n
5,5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: MLMAuction
Affected Version From: 1.0
Affected Version To: 1.2
Patch Exists: YES
Related CWE: CVE-2018-19072
CPE: a:auctionwebsitescript:mlm_auction
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2018

MLMAuction Script, SQL Injection Vulnerabilities

MLMAuction Script is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this vulnerability to manipulate SQL queries by injecting arbitrary SQL code. This may allow the attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

Mitigation:

Upgrade to the latest version of MLMAuction Script.
Source

Exploit-DB raw data: