vendor:
ITechBids v8.0
by:
Mr.SQL
8,8
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: ITechBids v8.0
Affected Version From: 8.0
Affected Version To: 8.0
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
ITechBids v8.0 Blind SQL Injection Exploit
This exploit is used to gain access to the ITechBids v8.0 database by exploiting a blind SQL injection vulnerability. The exploit uses a User Agent to send a malicious query to the server, which then returns a response indicating whether the query was successful or not. The exploit then uses this response to determine the value of the password stored in the database.
Mitigation:
Ensure that all user input is properly sanitized and validated before being used in a query.