vendor:
E-Uploader Pro
by:
~!Dok_tOR!~
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: E-Uploader Pro
Affected Version From: 1
Affected Version To: 1
Patch Exists: YES
Related CWE: N/A
CPE: a:scriptsfrenzy:e-uploader_pro
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: All
2008
E-Uploader Pro <= 1.0 SQL Injection Vulnerability
E-Uploader Pro version 1.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by sending malicious SQL queries to the vulnerable application. This can be done by sending a specially crafted HTTP request to the vulnerable application. The vulnerable application is vulnerable to both union-based and error-based SQL injection. The vulnerable application is also vulnerable to blind SQL injection. The vulnerable application is vulnerable to both GET and POST requests. The vulnerable application is vulnerable to both authenticated and unauthenticated users.
Mitigation:
The application should be configured to use the 'magic_quotes_gpc' feature. This feature will help to prevent SQL injection attacks. The application should also be configured to use parameterized queries. This will help to prevent SQL injection attacks.