vendor:
Scout Portal Toolkit
by:
JosS
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Scout Portal Toolkit
Affected Version From: 1.4.0 and prior
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Scout Portal Toolkit <= 1.4.0 (ParentId) Remote SQL Injection Exploit
Scout Portal Toolkit version 1.4.0 and prior are vulnerable to a remote SQL injection vulnerability. An attacker can exploit this vulnerability to gain access to the database and extract sensitive information such as usernames and passwords. The exploit is triggered by sending a specially crafted HTTP request to the vulnerable application.
Mitigation:
Upgrade to the latest version of Scout Portal Toolkit.