vendor:
Eventum
by:
James Bercegay
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Eventum
Affected Version From: 1.5.5 and earlier
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
MySQL Eventum <= v1.5.5 SQL Injection PoC
This exploit is a proof-of-concept for a SQL injection vulnerability in MySQL Eventum version 1.5.5 and earlier. The vulnerability is caused due to the improper sanitization of user-supplied input to the 'cat' parameter in the 'login.php' script. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Successful exploitation allows an attacker to gain access to the application with administrative privileges.
Mitigation:
Upgrade to the latest version of MySQL Eventum.