vendor:
SaphpLesson
by:
Jafer Al Zidjali
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: SaphpLesson
Affected Version From: SaphpLesson v4.3
Affected Version To: SaphpLesson v4.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
SaphpLesson v4.3 Exploit
This exploit is used to test for Blind SQL Injection vulnerability in SaphpLesson v4.3. It checks for the average response time and then tests for delayed response time. If the response time is more than 3 seconds, then the system is vulnerable to Blind SQL Injection.
Mitigation:
The vendor has released a public patch to address this vulnerability.