vendor:
Impleo Music Collection
by:
SirGod
7,5
CVSS
HIGH
SQL Injection (Auth Bypass) & Cross Site Scripting
89, 79
CWE
Product Name: Impleo Music Collection
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: NO
Related CWE: N/A
CPE: a:impleo:impleo_music_collection
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Impleo Music Collection 2.0 (SQL/XSS) Multiple Remote Vulnerabilities
Impleo Music Collection 2.0 is vulnerable to SQL Injection (Auth Bypass) and Cross Site Scripting. The vulnerable code is present in /admin/login.php, where the user input is not properly sanitized. An attacker can exploit this vulnerability to bypass authentication and execute arbitrary SQL commands. An attacker can also inject malicious JavaScript code in the application to perform Cross Site Scripting attacks.
Mitigation:
Input validation should be performed to prevent SQL Injection and Cross Site Scripting attacks.