vendor:
SN News
by:
WhiteCollarGroup
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: SN News
Affected Version From: 1
Affected Version To: 1.2
Patch Exists: NO
Related CWE:
CPE: a:sn_news:sn_news:1.2
Platforms Tested: Debian GNU/Linux, Windows 7 Ultimate
2012
SN News <= 1.2 SQL Injection
The SN News <= 1.2 application is vulnerable to SQL Injection. An attacker can exploit this vulnerability to gain unauthorized access to the application's database.
Mitigation:
To mitigate this vulnerability, developers should use parameterized queries or prepared statements to sanitize user input and prevent SQL Injection attacks.