vendor:
DataLife Engine
by:
1dt.w0lf
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: DataLife Engine
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2006
DataLife Engine sql injection exploit
This is a Perl script that exploits a SQL injection vulnerability in DataLife Engine. It allows an attacker to retrieve the password hash for a specific user by brute-forcing the characters of the hash.
Mitigation:
Apply the latest patch or upgrade to a newer version of DataLife Engine.