vendor:
Online Fire Reporting System
by:
Diyar Saadi
6.1
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Online Fire Reporting System
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: NO
Related CWE: CVE-2024-XXXX (Example)
CPE: a:phpgurukul:online_fire_reporting_system:1.2
Other Scripts:
https://www.infosecmatter.com/why-your-exploit-completed-but-no-session-was-created-try-these-fixes/, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/http/prtg_authenticated_rce, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/backupexec/ssl_uaf, https://www.infosecmatter.com/nessus-plugin-library/?id=18405, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/local/nscp_pe
Platforms Tested: Windows 11 + XAMPP 8.0.30
2024
Online Fire Reporting System SQL Injection Authentication Bypass
The vulnerability exists in the ofrs/admin/index.php script due to inadequate user input handling during the login process.
Mitigation:
To mitigate this issue, sanitize and validate user inputs to prevent SQL injection attacks.