vendor:
PlaySMS
by:
Noam Rathaus of Beyond Security Ltd.
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PlaySMS
Affected Version From: 0.7 and prior
Affected Version To: 0.7
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2004
PlaySMS version 0.7 and prior SQL Injection PoC
This is a proof-of-concept script demonstrating a SQL Injection vulnerability in PlaySMS version 0.7 and prior. The vulnerability allows an attacker to inject malicious SQL queries into the application, potentially leading to unauthorized access or manipulation of the database.
Mitigation:
Upgrade to a newer version of PlaySMS that includes a fix for the SQL Injection vulnerability. Additionally, sanitize and validate user input to prevent SQL Injection attacks.