vendor:
Online ID Generator 1.0
by:
nu11secur1ty
8.1
CVSS
CRITICAL
Remote Code Execution (RCE)
CWE
Product Name: Online ID Generator 1.0
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2023
Online ID Generator 1.0 – Remote Code Execution (RCE)
The Online ID Generator 1.0 software is vulnerable to remote code execution (RCE) due to a bypass login SQL injection vulnerability and a shell upload exploit. An attacker can exploit these vulnerabilities to execute arbitrary code on the target system.
Mitigation:
There is no information provided about mitigation or remediation for this vulnerability.