header-logo
Suggest Exploit
vendor:
FS Gigs Script
by:
Ihsan Sencan
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: FS Gigs Script
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:fortunescripts:fs_gigs_script:1.0
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2017

FS Gigs Script 1.0 – SQL Injection

The vulnerability allows an attacker to inject sql commands into the vulnerable parameter of the web application. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable parameter of the web application. The proof of concept involves sending a maliciously crafted HTTP request to the vulnerable parameter of the web application.

Mitigation:

Input validation should be used to prevent SQL injection attacks. Input validation should be applied on both syntactical and semantic level. Filtering input data on the client side is not sufficient. Input validation should be done on the server side. Parameterized queries should be used to prevent SQL injection attacks.
Source

Exploit-DB raw data: