vendor:
Ol Bookmarks Manager
by:
Cyber-Security
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Ol Bookmarks Manager
Affected Version From: 2000.7.4
Affected Version To: 2000.7.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Ol Bookmarks Manager 0.7.4 (root) Remote SQL Injection Vulnerabilities
The Ol Bookmarks Manager 0.7.4 (root) is vulnerable to remote SQL injection. An attacker can exploit this vulnerability by injecting malicious SQL queries into the 'id' parameter of the '/read/index.php' script. This allows the attacker to retrieve sensitive information from the database, such as passwords and login credentials.
Mitigation:
The vendor has not provided a patch for this vulnerability. Users are advised to update to a newer version of the Ol Bookmarks Manager or to implement strict input validation to prevent SQL injection attacks.