vendor:
Grapixel New Media 2
by:
Berk Dusunur
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Grapixel New Media 2
Affected Version From: v2
Affected Version To: v2
Patch Exists: NO
Related CWE: N/A
CPE: a:grapixel:grapixel_new_media_2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: MacosX
2018
Grapixel New Media 2 – ‘pageref’ SQL Injection
Time-Based sql injection is called a data extraction event with request response times with the server when there is no other way for it to extract aggressive data. It should be determined by sql injection type. I discovered blind time-based sql injection. Because single quotes didn't break the page structure, so I tried to get results using waitfor delay instead.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.