vendor:
Phpenpals
by:
Br0ly
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Phpenpals
Affected Version From:
Affected Version To: 1.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Phpenpals
The Phpenpals script version <= 1.1 is vulnerable to SQL Injection. By exploiting this vulnerability, an attacker can gain unauthorized access to the admin password and potentially retrieve sensitive information such as the contents of the /etc/passwd file.
Mitigation:
The vendor has not released any patch or mitigation for this vulnerability. It is recommended to upgrade to a newer version of the script that addresses this issue.