vendor:
Omnistar Article Manager Software
by:
Cold z3ro
7.5
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: Omnistar Article Manager Software
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Omnistar Article Manager Software (article.php) Remote SQL Injection Exploit
This exploit allows an attacker to perform a remote SQL injection attack on the Omnistar Article Manager Software. By manipulating the URL parameters, an attacker can retrieve sensitive information from the user database, such as usernames and passwords.
Mitigation:
To mitigate this vulnerability, it is recommended to update to the latest version of the Omnistar Article Manager Software. Additionally, input validation and parameterized queries should be implemented to prevent SQL injection attacks.