vendor:
StreetGuessr Game
by:
Ihsan Sencan
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: StreetGuessr Game
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Win7 x64, Kali Linux x64
2017
Joomla! Component StreetGuessr Game v1.0 – SQL Injection
An attacker can exploit a SQL injection vulnerability in Joomla! Component StreetGuessr Game v1.0 to execute arbitrary SQL commands by sending a specially crafted HTTP request containing malicious SQL statements to the vulnerable application. The attacker can use the 'Procedure Analyse' and 'extractvalue' functions to extract the version of the database server.
Mitigation:
Input validation should be used to prevent SQL injection attacks. Parameterized queries should be used to prevent SQL injection attacks.