vendor:
Flinx
by:
Houssamix
7.5
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: Flinx
Affected Version From: 1.3 & Below
Affected Version To: 1.3 & Below
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Flinx 1.3 & Below Remote SQL Injection Vulnerability
A vulnerability exists in Flinx 1.3 & below which allows an attacker to inject arbitrary SQL commands. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code in the 'id' parameter in category.php. An attacker can use this vulnerability to gain access to the database and extract sensitive information such as usernames and passwords.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to upgrade to the latest version of Flinx.