vendor:
KLINK
by:
Andr?s G?mez
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: KLINK
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
KLINK Sql Injection Vulnerability
An attacker may execute arbitrary SQL statements on the vulnerable system. This may compromise the integrity of the database and/or expose sensitive information. Malicious users may inject SQL querys into a vulnerable application to fool a user in order to gather data from them or see sensible information.
Mitigation:
Add preg_replace() to the template index.php after the first <?php decelaration.