vendor:
cpDynaLinks
by:
ka0x
7.5
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: cpDynaLinks
Affected Version From: 01.02
Affected Version To: 01.02
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
cpDynaLinks 1.02 Remote SQL Injection exploit
This exploit allows an attacker to perform a remote SQL injection attack on cpDynaLinks version 1.02. By exploiting the vulnerability, the attacker can retrieve the admin username and password from the database.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of cpDynaLinks or implement proper input validation and sanitization to prevent SQL injection attacks.