vendor:
goffgrafix Design
by:
Ashiyane Digital Security Team
9,3
CVSS
HIGH
SQL Injection
89
CWE
Product Name: goffgrafix Design
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: N/A
CPE: a:goffgrafix_design:goffgrafix_design
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
goffgrafix Design’s SQL Injection Vulnerability
goffgrafix Design is vulnerable to SQL injection attacks. Attackers can exploit this vulnerability to gain access to the underlying database and execute arbitrary SQL commands. The vulnerability exists due to insufficient input validation in the "id" parameter of the "page.php" and "designer.php" scripts. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL commands.
Mitigation:
To mitigate this vulnerability, input validation should be implemented to ensure that user-supplied data is properly sanitized.