vendor:
Samsara
by:
_mRkZ_, WaRWolFz Crew
8,8
CVSS
HIGH
Remote Blind SQL Injection
89
CWE
Product Name: Samsara
Affected Version From: 3.1
Affected Version To: 3.1
Patch Exists: YES
Related CWE: N/A
CPE: a:exoopport:samsara
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2010
E-Xoopport – Samsara <= v3.1 (eCal Module) Remote Blind SQL Injection Exploit
E-Xoopport is a web application that is vulnerable to a Remote Blind SQL Injection vulnerability in its eCal module. This vulnerability allows an attacker to gain access to the application's database and extract sensitive information. The exploit is written in Perl and requires the attacker to have access to the eCal module. The exploit is triggered by sending a specially crafted HTTP request to the application.
Mitigation:
The application should be patched to prevent the vulnerability from being exploited. Additionally, the application should be configured to only allow authenticated users to access the eCal module.