vendor:
CJ Ultra Plus
by:
-SmoG-
8.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: CJ Ultra Plus
Affected Version From: v1.0.4
Affected Version To: v1.0.4
Patch Exists: NO
Related CWE: N/A
CPE: a:cj-ultra-plus:cj_ultra_plus
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2008
CJ Ultra Plus <= v1.0.4 Cookie SQL Injection
CJ Ultra Plus is vulnerable to a SQL injection vulnerability in the SID cookie. An attacker can exploit this vulnerability to extract the admin hash from the settings table.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries.