vendor:
Fusebox
by:
Shamus
N/A
CVSS
N/A
Remote SQL Injection
89
CWE
Product Name: Fusebox
Affected Version From: -
Affected Version To: -
Patch Exists: NO
Related CWE: N/A
CPE: a:fusebox:fusebox
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
fusebox (ProductList.cfm?CatDisplay) Remote SQL Injection Vulnerability
A vulnerability exists in fusebox (ProductList.cfm?CatDisplay) which allows an attacker to inject arbitrary SQL queries. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL queries to the vulnerable application. This can result in the disclosure of sensitive information from the database, modification of data, or even execution of arbitrary system commands.
Mitigation:
N/A