vendor:
PHPads
by:
Felipe Andrian Peixoto
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PHPads
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: Yes
Related CWE: N/A
CPE: a:blondish.net:phpads:2.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 and Gnu/Linux
2019
Sql Injection on PHPads Version 2.0 based on Pixelledads 1.0
A SQL injection vulnerability exists in PHPads Version 2.0 based on Pixelledads 1.0. The vulnerable code is located in the click.php3 file. An attacker can send a specially crafted request to the vulnerable file and execute arbitrary SQL commands in application's database. The vulnerable code is located in the click.php3 file. An attacker can send a specially crafted request to the vulnerable file and execute arbitrary SQL commands in application's database.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to upgrade to the latest version of the software.