vendor:
Biblioteca
by:
Salvatore Fresta aka Drosophila
8,8
CVSS
HIGH
Multiple Blind SQL Injection and Multiple SQL Injection
89, 89, 89
CWE
Product Name: Biblioteca
Affected Version From: 1.0 Beta
Affected Version To: 1.0 Beta
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Biblioteca 1.0 Beta Joomla Component Multiple SQL Injection Vulnerabilities
The parameter testo passed to bi.php (site and admin frontends) is properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The parameter testo passed to stampa.php, pdf.php and models/biblioteca.php (when 'view' is set to 'biblioteca') is properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Mitigation:
No fix available.