vendor:
Advanced comment system
by:
Rafael Pedrero
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Advanced comment system
Affected Version From: Advanced comment system v1.0
Affected Version To: Advanced comment system v1.0
Patch Exists: NO
Related CWE: CVE-2018-18619
CPE: a:plohni:advanced_comment_system:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: All
2018
SQL injection in Advanced comment system v1.0
PHP page internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in the 'page' parameter.
Mitigation:
The product is discontinued.