vendor:
Component n-forms
by:
The Moorish
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Component n-forms
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Mambot Component n-forms Blind SQL Injection Exploit
Mambot Component n-forms Blind SQL Injection Exploit is a perl script which exploits a vulnerability in the Mambot Component n-forms. It allows an attacker to extract the MD5 hash of the user's password from the database. The exploit takes the host, path, userid, and form id as arguments and uses a loop to iterate through the characters of the MD5 hash.
Mitigation:
The vulnerability can be mitigated by applying the latest security patches and ensuring that all user input is properly sanitized.