vendor:
Snitz 2000
by:
Soroush Dalili
N/A
CVSS
N/A
SQL Injection
CWE
Product Name: Snitz 2000
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2007
A user can gain admin level in snitz 2000 by SQL Injection
A user can gain admin level in the forum and can access to the forum. It is because of a SQL Injection in 'Active.asp'. After login to your VICTIM forum, execute the provided HTML exploit.
Mitigation:
Update to the latest version of Snitz 2000