vendor:
Red Dot CMS
by:
Mark Crowther and Rodrigo Marcos
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Red Dot CMS
Affected Version From: 7.5
Affected Version To: 7.5
Patch Exists: NO
Related CWE: N/A
CPE: a:red_dot_solutions:red_dot_cms:7.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Python
2009
RED DOT CMS 7.5 database enumeration
RED DOT CMS 7.5 is vulnerable to SQL injection. This exploit allows an attacker to enumerate databases, tables, columns and data from the vulnerable application. The exploit is written in Python and can be used to enumerate databases, tables, columns and data from the vulnerable application.
Mitigation:
Input validation and sanitization should be used to prevent SQL injection attacks.