vendor:
XOOPS Module eCal
by:
ajann
7.5
CVSS
HIGH
Remote BLIND SQL Injection
CWE
Product Name: XOOPS Module eCal
Affected Version From: 2.24
Affected Version To: 2.24
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
XOOPS Module eCal 2.24 <= (display.php) Remote BLIND SQL Injection Exploit
This exploit allows an attacker to perform a remote BLIND SQL injection attack on XOOPS Module eCal version 2.24 and earlier. The attacker can retrieve the admin username and password from the MySQL user table.
Mitigation:
Upgrade to a patched version of XOOPS Module eCal.