vendor:
PerlDesk
by:
deluxe89 and Astovidatu
5.5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: PerlDesk
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2005
PerlDesk exploit
This exploit takes advantage of a SQL injection vulnerability in PerlDesk. It allows an attacker to extract usernames and passwords from the users table.
Mitigation:
Apply proper input validation and sanitization to prevent SQL injection attacks. Update to a patched version of PerlDesk.