vendor:
Maian Uploader
by:
KedAns-Dz
7,5
CVSS
HIGH
SQL Injection, Cross-Site Scripting, Full Path Disclosure
89, 79, 200
CWE
Product Name: Maian Uploader
Affected Version From: 4.0
Affected Version To: 4.0
Patch Exists: YES
Related CWE: N/A
CPE: a:maian_scripts:maian_uploader
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Maian Uploader Multiple Security Vulnerabilities
Maian Uploader is prone to multiple security vulnerabilities, including an SQL-injection vulnerability, multiple cross-site scripting vulnerabilities, and a full path disclosure vulnerability. Attackers can exploit these issues to access or modify data, exploit latent vulnerabilities in the underlying database, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, and steal cookie-based authentication credentials. Maian Uploader 4.0 is vulnerable; other versions may also be affected.
Mitigation:
Users should upgrade to the latest version of Maian Uploader. Additionally, users should ensure that all input is validated and filtered before being used in SQL queries.