vendor:
Event Script PHP
by:
Vulnerability Laboratory Research Team
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Event Script PHP
Affected Version From: Event Script PHP v1.1
Affected Version To: Event Script PHP v1.1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Event Script PHP v1.1 CMS – Multiple Web Vulnerabilites
The Vulnerability Laboratory Research Team discovered multiple SQL Injection vulnerabilites in Event Script PHP v1.1 CMS. The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms without user inter action. The vulnerabilities are located in the eventscript.php file and the bound parameters p & id. The sql injection vulneability can be exploited by remote attackers with low required user inter action. Successful exploitation of the vulnerability results in dbms & application compromise.
Mitigation:
Edit the source code to prevent sql injection attacks.