vendor:
Add a link
by:
JosS
7.5
CVSS
HIGH
Multiple Security Vulnerabilities
89, 264
CWE
Product Name: Add a link
Affected Version From: 4
Affected Version To: 4
Patch Exists: NO
Related CWE: N/A
CPE: addalink
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Perl
2008
Add a link <= 4 Arbitrary Admin Access Vulnerability Exploit
Add a link is prone to multiple security vulnerabilities, including multiple security-bypass issues and an SQL-injection issue. Exploiting the security-bypass issues may allow an attacker to bypass certain security restrictions and perform unauthorized actions. The attacker can exploit the SQL-injection issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database. This will compromise the application and may aid in further attacks.
Mitigation:
Ensure that all user-supplied input is validated and filtered before being used in SQL queries. Ensure that all user-supplied input is validated and filtered before being used in SQL queries. Ensure that all user-supplied input is validated and filtered before being used in SQL queries. Ensure that all user-supplied input is validated and filtered before being used in SQL queries.