vendor:
Classifieds System
by:
ByALBAYX
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Classifieds System
Affected Version From: SkyPortal Classifieds System v0.12
Affected Version To: SkyPortal Classifieds System v0.12
Patch Exists: YES
Related CWE: N/A
CPE: skyportal.net/downloads/modules/mod_classifieds_0_12.zip
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
SkyPortal Classifieds System v0.12
SkyPortal Classifieds System v0.12 is vulnerable to SQL injection. An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable scripts. This can allow the attacker to gain access to sensitive information stored in the database.
Mitigation:
Apply the latest security patches and ensure that all user input is properly sanitized.