vendor:
PHP Hazir Rent A Car Sitesi Scripti V2
by:
Ahmet Ümit BAYRAM
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PHP Hazir Rent A Car Sitesi Scripti V2
Affected Version From: V2
Affected Version To: V2
Patch Exists: NO
Related CWE:
CPE: a:jettweb:php_hazir_rent_a_car_sitesi_scripti_v2
Platforms Tested: Kali Linux
2019
Jettweb PHP Hazir Rent A Car Sitesi Scripti V2 – ‘arac_kategori_id’ SQL Injection
The Jettweb PHP Hazir Rent A Car Sitesi Scripti V2 is vulnerable to SQL Injection through the 'arac_kategori_id' parameter. By injecting a specially crafted payload, an attacker can manipulate the SQL query and potentially gain unauthorized access to the database.
Mitigation:
To mitigate this vulnerability, input validation and parameterized queries should be implemented to prevent SQL Injection attacks. The vendor should release a patch or update to fix this issue.