vendor:
Mambo Component SimpleFAQ
by:
k1tk4t
7.5
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: Mambo Component SimpleFAQ
Affected Version From: SimpleFAQ V2.11
Affected Version To: SimpleFAQ V2.11
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Mambo Component SimpleFAQ V2.11 – Remote SQL Injection
The Mambo Component SimpleFAQ V2.11 is vulnerable to remote SQL injection. An attacker can exploit this vulnerability by sending a specially crafted URL to the target system. This allows the attacker to execute arbitrary SQL queries and potentially gain unauthorized access to the database.
Mitigation:
The vendor has not released a patch for this vulnerability. Users are advised to upgrade to a newer version of the software or use an alternative component that is not vulnerable to SQL injection.