vendor:
e-ticketing
by:
Mark Stanislav
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: e-ticketing
Affected Version From: Released on 2011-11-30
Affected Version To: Released on 2011-11-30
Patch Exists: NO
Related CWE: CVE-2012-1673
CPE: a:e-ticketing:e-ticketing
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
e-ticketing’ SQL Injection (CVE-2012-1673)
A vulnerability exists in loginscript.php that allows for SQL injection of the 'user_name' and 'password' POST parameters.
Mitigation:
Do not use this software, no patched version exists at this time.