vendor:
Online AgroCulture Farm Management System
by:
Tarun Sehgal
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Online AgroCulture Farm Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro 10.0.18363 N/A Build 18363 + XAMPP V3.2.4
2020
Online AgroCulture Farm Management System 1.0 – ‘uname’ SQL Injection
This exploit allows an attacker to perform an SQL injection attack on the 'uname' parameter of the Online AgroCulture Farm Management System 1.0. By injecting a specially crafted payload, the attacker can retrieve sensitive information from the database, such as the database name and MariaDB version.
Mitigation:
To mitigate this vulnerability, the vendor should implement proper input validation and parameterized queries to prevent SQL injection attacks.