vendor:
elproLOG MONITOR-WebAccess
by:
Vulnerability Laboratory Research Team
6,7
CVSS
HIGH
Remote Blind SQL Injection
89
CWE
Product Name: elproLOG MONITOR-WebAccess
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: YES
Related CWE: N/A
CPE: a:elpro-buchs_ag:elprolog_monitor_webaccess:2.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
elproLOG MONITOR WebAccess 2.1 – Multiple Vulnerabilities
A remote blind SQL Injection web vulnerability is detected in the ELPRO elproLOG MONITOR WebAccess v2.1 Web-Application. The SQL Injection vulnerability allows an attacker (remote) to execute/inject own SQL commands in the vulnerable web-application database management system. The sql injection vulnerability is located in the strend.php file. Remote attackers can inject own sql commands by attacking via http GET method request the affected id parameter of the vulnerable strend.php file.
Mitigation:
Apply the latest security patches and updates to the web-application and database management system.