vendor:
LocatePC
by:
Ligatt Security
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: LocatePC
Affected Version From: 01.05
Affected Version To: 01.05
Patch Exists: NO
Related CWE: N/A
CPE: a:ligatt_security:locatepc
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
LocatePC 1.05 Arbitrary SELECT Query Vulnerability
A vulnerability in LocatePC 1.05 allows an attacker to execute arbitrary SELECT queries against the LocatePC and 'mysql' database. This can be used to extract information from the database, such as user names, MAC addresses, last login IPs, and program logins. It may also be possible to upload arbitrary files from each user's computer to the LocatePC database, and then to later extract those files from the database. Activating the software's keylogging functionality is also possible.
Mitigation:
DON'T USE LOCATEPC!!!