vendor:
Snitz Forums 2000
by:
Unknown
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Snitz Forums 2000
Affected Version From: Snitz Forums 3.3.03
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:snitz:forums:2000
Platforms Tested: Windows
Unknown
Remote command execution against Snitz Forums
A remote attacker can inject SQL into queries made by the register.asp script, potentially resulting in disclosure of sensitive information or modification of data. This vulnerability may also be leveraged to exploit vulnerabilities in the underlying database.
Mitigation:
Apply patches or updates provided by the vendor. Implement input validation and parameterized queries to prevent SQL injection attacks.