vendor:
com_abc
by:
AntiSecurity
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: com_abc
Affected Version From: 1.1.7
Affected Version To: 1.1.7
Patch Exists: NO
Related CWE: N/A
CPE: a:airiny:com_abc
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2010
ABC Joomla Extension SQL Injection Exploit
ABC Joomla Extension is vulnerable to SQL Injection. An attacker can exploit this vulnerability by sending a crafted HTTP request with malicious SQL query to the vulnerable application. This can allow the attacker to gain access to the admin account and extract sensitive information from the database.
Mitigation:
The application should use parameterized queries to prevent SQL injection attacks.