vendor:
DigiRez
by:
ajann
7.5
CVSS
HIGH
Remote BLIND SQL Injection
CWE
Product Name: DigiRez
Affected Version From: DigiRez <= V3.4
Affected Version To: DigiRez <= V3.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
DigiRez <= V3.4 (book_id) Remote BLIND SQL Injection Exploit
The DigiRez <= V3.4 (book_id) Remote BLIND SQL Injection exploit allows an attacker to execute SQL queries and retrieve sensitive information from the database.
Mitigation:
Apply the latest patch or upgrade to a newer version of DigiRez.