vendor:
RadNICS Gold v5
by:
Moudi
9,3
CVSS
HIGH
SQL Injection
89
CWE
Product Name: RadNICS Gold v5
Affected Version From: RadNICS Gold v5
Affected Version To: RadNICS Gold v5
Patch Exists: YES
Related CWE: CVE-2007-6015
CPE: a:radscripts:radnics_gold_v5
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2007-1114/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2007-6015/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2007-6015/, https://www.rapid7.com/db/vulnerabilities/apple-osx-samba-cve-2007-6015/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2007-1117/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2007-1114/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2007-1117/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2007-6015/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-ffcbd42d-a8c5-11dc-bec2-02e0185f8d72/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2007
RadNICS Gold v5 Multiple Remote Vulnerabilities
RadNICS Gold v5 is vulnerable to SQL injection. An attacker can exploit this vulnerability to gain access to the database and execute arbitrary SQL commands. The vulnerability is located in the "fid" parameter of the "view_forum" module. An attacker can inject malicious SQL code to the "fid" parameter value in order to execute arbitrary SQL commands.
Mitigation:
Upgrade to the latest version of RadNICS Gold v5.