vendor:
REScript
by:
Mr.SQL
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: REScript
Affected Version From: REScript V.0.99 Beta
Affected Version To: REScript V.0.99 Beta
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Remote SQL Injection Vulnerability ( listings.php op )
A vulnerability in the REScript V.0.99 Beta web application allows an attacker to inject arbitrary SQL commands via the 'op' parameter in the 'listings.php' script. This can be exploited to gain access to the database and to disclose sensitive information such as user credentials.
Mitigation:
Input validation should be used to prevent SQL injection attacks.