vendor:
Rix4Web Portal
by:
L0n3ly-H34rT
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Rix4Web Portal
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux, Windows
2013
Rix4Web Portal Remote Blind SQL Injection Vulnerability
The Rix4Web Portal is vulnerable to blind SQL injection. This can be exploited by injecting malicious SQL queries into the 'dir_link' parameter. An attacker can execute arbitrary SQL commands and retrieve sensitive information from the database.
Mitigation:
To mitigate this vulnerability, the vendor should sanitize user input and use parameterized queries to prevent SQL injection attacks. It is recommended to update to a patched version of the software.