vendor:
Buddy Zone
by:
t0pP8uZz & xprog
N/A
CVSS
N/A
SQL Injection
CWE
Product Name: Buddy Zone
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Buddy Zone Version 1.5 SQL Injection Vulnerability
Remote sql injection in view_sub_cat.php cat_id, able to pull username/passwords of their admin and user accounts.
Mitigation:
Unknown