vendor:
DigiAffiliate
by:
ajann
7.5
CVSS
HIGH
Remote Blind SQL Injection
CWE
Product Name: DigiAffiliate
Affected Version From: DigiAffiliate version 1.4
Affected Version To: DigiAffiliate version 1.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
DigiAffiliate <= V1.4 Remote Blind SQL Injection Exploit
This exploit allows an attacker to perform blind SQL injection on DigiAffiliate version 1.4. By injecting a specially crafted SQL query, the attacker can retrieve sensitive information such as login credentials and personal details of the admin user.
Mitigation:
To mitigate this vulnerability, users should update to the latest version of DigiAffiliate. Additionally, input validation and parameterized queries should be implemented to prevent SQL injection attacks.