vendor:
Escort Agency CMS
by:
NoNameMT
8.8
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Escort Agency CMS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2011
Escort Agency CMS Blind SQL Injection Vunerability
The vulnerability exists in Escort Agency CMS, which is a web application developed by Escort Website Design. It allows an attacker to inject malicious SQL queries into the application, which can be used to extract sensitive information from the database. The vulnerability can be exploited by sending a specially crafted HTTP request containing a malicious SQL query to the application. The application will then execute the query and return the results to the attacker.
Mitigation:
The application should be configured to use parameterized queries to prevent SQL injection attacks. Additionally, the application should be configured to use a web application firewall to detect and block malicious requests.