vendor:
The Unit Command Climate Assessment and Survey System (UCCASS)
by:
dun
N/A
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: The Unit Command Climate Assessment and Survey System (UCCASS)
Affected Version From: 1.8.1 and previous
Affected Version To: 1.8.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2012
UCCASS <= v1.8.1 Blind SQL Injection Vulnerability
The UCCASS survey script (version <= 1.8.1) is vulnerable to blind SQL injection. An attacker can exploit this vulnerability by manipulating the 'sid' parameter in the 'filter.php' file. By injecting a specially crafted SQL query, the attacker can bypass authentication or retrieve sensitive information from the database.
Mitigation:
Upgrade to a fixed version of UCCASS