vendor:
by:
Mr.SQL
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
MojoAuto Blind SQL Injection Exploit
This is a Perl script that exploits the MojoAuto blind SQL injection vulnerability in the mojoAuto.cgi script. It allows an attacker to extract the MD5 hash of a password.
Mitigation:
The vendor should release a patch to fix the SQL injection vulnerability in the mojoAuto.cgi script.