vendor:
phpVID
by:
t0pP8uZz & xprog
5.5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: phpVID
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
phpVID SQL Injection Vulnerabilities
The exploit allows an attacker to retrieve multiple admin/user credentials by injecting SQL queries.
Mitigation:
To mitigate the vulnerability, input validation and parameterized queries should be implemented.