vendor:
MySQL Blob Uploader
by:
Özkan Mustafa Akkus (AkkuS)
7.5
CVSS
HIGH
SQL Injection / Cross-Site Scripting
89, 79
CWE
Product Name: MySQL Blob Uploader
Affected Version From: 1.7
Affected Version To: 1.7
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
MySQL Blob Uploader 1.7 – ‘home-file-edit.php’ SQL Injection / Cross-Site Scripting
MySQL Blob Uploader 1.7 is vulnerable to SQL Injection and Cross-Site Scripting. An attacker can exploit this vulnerability by sending malicious payloads to the vulnerable parameters. For SQL Injection, the attacker can use boolean-based blind, error-based, AND/OR time-based blind and UNION query payloads. For Cross-Site Scripting, the attacker can use a malicious script payload.
Mitigation:
Input validation should be done on the server-side to prevent malicious payloads from being executed.