vendor:
GetMyOwnArcade
by:
RoXur777
5.5
CVSS
MEDIUM
SQL-Injection
89
CWE
Product Name: GetMyOwnArcade
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
GetMyOwnArcade (search.php) ($query) SQL-Injection
The vulnerability exists in the 'query' parameter of the search.php page in GetMyOwnArcade. The parameter is not properly filtered before being used in a database query, allowing an attacker to inject malicious SQL code. By using the UNION-SELECT technique, an attacker can extract sensitive information such as usernames and passwords from the database.
Mitigation:
To mitigate this vulnerability, the application should properly validate and sanitize user input before using it in a database query. This can be done by using parameterized queries or prepared statements.