vendor:
Project Management Software
by:
Vicente Aguilera Diaz
6,8
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: Project Management Software
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2013-6164
CPE: a:projector_ria:projector_ria
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
SQL Injection vulnerability in Project’Or RIA
Has been detected a SQL Injection vulnerability in the 'Affectations' functionality of this application. The affected resource and parameter are the following: Resource: /view/objectDetail.php Parameter: objectId This vulnerability allows the execution of arbitrary SQL code against the database, and arbitrary access to the file system.
Mitigation:
Ensure that user input is validated and filtered before being used in SQL queries.