vendor:
CMS-School 2005
by:
Maghribi WnaftakhaR
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: CMS-School 2005
Affected Version From: CMS-School 2005
Affected Version To: CMS-School 2005
Patch Exists: YES
Related CWE: N/A
CPE: a:cms-school:cms-school_2005
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 + Apache 2.0.54 + PHP 5.0.3 + MySQL 4.1.11
2005
CMS-School 2005 (showarticle.php) Remote SQL injection Vulnerability
CMS-School 2005 is prone to a remote SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this issue to manipulate SQL queries by injecting arbitrary SQL code. This may allow the attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Mitigation:
Upgrade to the latest version of CMS-School 2005.