vendor:
OpenDocMan
by:
Mehmet EMIROGLU
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: OpenDocMan
Affected Version From: 1.3.2004
Affected Version To: 1.3.2004
Patch Exists: NO
Related CWE:
CPE: a:opendocman:opendocman:1.3.4
Platforms Tested: Wamp64, @Win
2019
OpenDocMan 1.3.4 – ‘where’ SQL Injection
This exploit allows an attacker to inject SQL code in the 'where' parameter of the search.php page in OpenDocMan 1.3.4, which can lead to unauthorized access or manipulation of the database.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate user input before using it in SQL queries, and to use prepared statements or parameterized queries.