vendor:
Gallery Personals
by:
3spi0n
5,5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: Gallery Personals
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: CVE-2018-19072
CPE: a:scriptsgenie:gallery_personals
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2018
Gallery Personals Script SQL Injection Vulnerabilities
Gallery Personals Script is prone to a SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this vulnerability to manipulate the queries that are executed on the underlying database, allowing for the manipulation or disclosure of arbitrary data.
Mitigation:
Upgrade to the latest version of Gallery Personals Script.