vendor:
Free
by:
Stack
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Free
Affected Version From: 4.0.34P
Affected Version To: 4.0.34P
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Powered by WSN Links Free 4.0.34P Blind SQL Injection
This exploit is used to gain access to the user and password of a WSN Links Free 4.0.34P website. The exploit uses a blind SQL injection technique to gain access to the user and password. The exploit is done by sending a series of requests to the website with different parameters and checking the response. If the response is correct, the exploit will continue to the next step. The exploit will then use a brute force technique to gain access to the user and password.
Mitigation:
The best way to mitigate this vulnerability is to ensure that all user input is properly sanitized and validated before being used in any SQL queries.