vendor:
XOOPS Module Library
by:
ajann
7.5
CVSS
HIGH
BLIND SQL Injection
CWE
Product Name: XOOPS Module Library
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
XOOPS Module Library (viewcat.php) BLIND SQL Injection Exploit
This script exploits a blind SQL injection vulnerability in the XOOPS Module Library (viewcat.php) script. It allows an attacker to extract the username and password from the xoops_users table by injecting a UNION SELECT statement.
Mitigation:
Patch or update the XOOPS Module Library script to fix the SQL injection vulnerability.