vendor:
FileBox - File Hosting & Sharing Script
by:
Scripts Apart
5.5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: FileBox - File Hosting & Sharing Script
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: NO
Related CWE:
CPE: a:scriptsapart:filebox:1.5
Platforms Tested: Windows 7, Ubuntu 11
2011
FileBox – File Hosting & Sharing Script 1.5 SQL Injection
There is a SQL Vulnerability in the FileBox Script. The sqli is MYSQL_Error based one.
Mitigation:
The vendor should release a patch to fix the SQL Injection vulnerability.