vendor:
CMS WebBlizzard
by:
Bl@ckbe@rD
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: CMS WebBlizzard
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
CMS WebBlizzard Blind SQL Injection Exploit
This exploit allows an attacker to inject malicious SQL queries into a vulnerable web application. The exploit is a blind SQL injection, meaning that the attacker can not see the results of the query, but can determine if the query was successful or not. The exploit is used to gain access to the database and extract sensitive information such as usernames and passwords.
Mitigation:
Input validation and proper sanitization of user input can help prevent SQL injection attacks.