vendor:
Flexphplink Pro
by:
x0r
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Flexphplink Pro
Affected Version From: 0.0.7
Affected Version To: 0.0.7
Patch Exists: NO
Related CWE:
CPE: a:flexphplink:flexphplink_pro:0.0.7
Platforms Tested:
2008
Flexphplink Pro SQL Injection Vulnerability
The vulnerability exists in the usercheck.php file of the Flexphplink Pro CMS. It allows an attacker to execute arbitrary SQL queries by manipulating the 'username' and 'password' parameters. By providing the SQL code ' or '1=1, an attacker can bypass authentication and gain unauthorized access to the system.
Mitigation:
The vendor should release a patch or update to fix the SQL injection vulnerability. In the meantime, users are advised to restrict access to the affected files or implement input validation and parameterized queries to mitigate the risk.