TSEP <=0.942.02 Vulnerabilities
The vulnerability exists due to insufficient sanitization of user-supplied input in the 'deleteRank' and 'percent' parameters of '/admin/rankform.php' script. A remote attacker can send a specially crafted HTTP request with malicious SQL statements to the vulnerable script and execute arbitrary SQL commands in application's database. For Blind SQL-Inj, the attacker can send a specially crafted HTTP request with malicious SQL statements to the vulnerable script and execute arbitrary SQL commands in application's database. For SQL-Inj, the attacker can send a specially crafted HTTP request with malicious SQL statements to the vulnerable script and execute arbitrary SQL commands in application's database, which can be used to extract admin name & pwd.