vendor:
Game Portal Manager
by:
t0pP8uZz & xprog
5.5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: Game Portal Manager
Affected Version From: 1.7
Affected Version To: 1.7
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Game Portal Manager v1.7 SQL Injection Vulnerability
The browser cookie is sql injectable, allowing admin access without knowing the password.
Mitigation:
Implement input validation and parameterized queries to prevent SQL injection.