vendor:
Product Sale Framework
by:
b3hz4d
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Product Sale Framework
Affected Version From: v0.1 beta
Affected Version To: v0.1 beta
Patch Exists: NO
Related CWE: N/A
CPE: a:product_sale_framework:product_sale_framework:0.1beta
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Product Sale Framework sql injection Vulnerability
A vulnerability exists in Product Sale Framework v0.1 beta, where an attacker can inject malicious SQL queries into the customer.forumtopic.php page, allowing them to gain access to the admin username and password.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries.