vendor:
b2ePMS
by:
Jean Pascal Pereira
7,5
CVSS
HIGH
SQL Injection, Authentication Bypass
89
CWE
Product Name: b2ePMS
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:berlios:b2epms:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
b2ePMS 1.0 Authentication Bypass Vulnerability
The remote attacker has the possibility to execute arbitrary SQL Code and bypass the user authentication. To exploit this vulnerability, the attacker needs to perform a login with the following data: Username: admin' OR '1='1 and Password: x
Mitigation:
Input validation and sanitization should be done to prevent SQL Injection attacks.