vendor:
cp_creator
by:
Sina Yazdanmehr (R3d.W0rm)
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: cp_creator
Affected Version From: 2.7.2001
Affected Version To: 2.7.2001
Patch Exists: YES
Related CWE: N/A
CPE: a:cp_creator:cp_creator
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
cP Creator v2.7.1 Remote Sql Injection
A vulnerability exists in cP Creator v2.7.1 which allows an attacker to inject malicious SQL queries into the application. This can be exploited to gain access to the application's database and potentially gain access to sensitive information. The vulnerability is due to insufficient sanitization of user-supplied input in the 'page' and 'task' parameters of the 'support' page. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL queries.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to apply the patch as soon as possible.