vendor:
Escort Service Begleitagentur
by:
NoNameMT
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Escort Service Begleitagentur
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:media-products:escort-service-begleitagentur:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2011
Exploit Title: Escort und Begleitservice Agentur Script SQL Injection
The vulnerability exists due to insufficient filtration of user-supplied input in 'custid' parameter in 'show_profile.php' script. A remote attacker can execute arbitrary SQL commands in application's database and gain access to sensitive data.
Mitigation:
Input validation should be used to prevent SQL injection attacks. All user-supplied input should be validated and filtered before passing to the database.