vendor:
Public Media Manager
by:
learn3r hacker from Nepal
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Public Media Manager
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Public Media Manager SQLi vulns
This product, an online NEWS CMS, suffers from SQL injection in login so that we can bypass the login system. Also, it suffers from SQLi in the GET variables which can be exploited to get different information from the database.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.