vendor:
Baby Names Search Engine
by:
Özkan Mustafa Akkus (AkkuS)
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Baby Names Search Engine
Affected Version From: 1
Affected Version To: 2
Patch Exists: YES
Related CWE: N/A
CPE: a:mediageni:baby_names_search_engine
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
Baby Names Search Engine v1.0 – ‘a’ SQL Injection
The vulnerability allows an attacker to inject sql commands from search section with 'a' parameter.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.