vendor:
Enigma Haber
by:
nukedx.com, milw0rm.com
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Enigma Haber
Affected Version From: 4.3
Affected Version To: 4.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Enigma Haber <= 4.3 Multiple Remote SQL Injection Vulnerabilities
Multiple Remote SQL Injection Vulnerabilities exist in Enigma Haber <= 4.3. An attacker can exploit these vulnerabilities to gain access to sensitive information such as passwords, usernames, emails, etc. The vulnerable parameters are 'id', 'yo', 'ara', 'ko', 'k', 'd', 'e', 'ay', 'yil', 'e_kad', 'yid', 'bid', 'hid', 'o', 'kid', 'tur', 's'. An attacker can send malicious SQL queries to the vulnerable parameters to gain access to sensitive information.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to update the software to the latest version.