vendor:
PHPKB Knowledge Base Software
by:
R3d-D3v!L
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PHPKB Knowledge Base Software
Affected Version From: v2 Multilanguage Support
Affected Version To: v2 Multilanguage Support
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
PHPKB Knowledge Base Software v2 Multilanguage Support Multi SQL Injection Vulnerabilities
Two SQL Injection vulnerabilities were discovered in PHPKB Knowledge Base Software v2 Multilanguage Support. The first vulnerability is located in the 'email.php' file with the vulnerable parameter 'ID'. The second vulnerability is located in the 'comment.php' file with the vulnerable parameter 'ID'. An attacker can inject malicious SQL queries to gain access to sensitive information from the database.
Mitigation:
Input validation should be used to prevent SQL injection attacks.