vendor:
JSPMySQL Administrador
by:
hyp3rlinx
3
CVSS
HIGH
CSRF & XSS
352, 79
CWE
Product Name: JSPMySQL Administrador
Affected Version From: JSPMySQL Administrador v.1
Affected Version To: JSPMySQL Administrador v.1
Patch Exists: YES
Related CWE: N/A
CPE: a:mfpledon:jspmysql_administrador
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web
2015
JSPMySQL Administrador CSRF & XSS
No CSRF token exists allowing remote attackers to run arbitrary SQL commands on the MySQL database. XSS entry point exists on the listaBD2.jsp web page opening up the application for client side browser code execution.
Mitigation:
Upgrade to the latest version of JSPMySQL Administrador.