vendor:
Sniggabo CMS
by:
Lidloses_Auge
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Sniggabo CMS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Sniggabo CMS – Remote SQL Injection Exploit
This exploit allows an attacker to gain access to the admin panel of a vulnerable Sniggabo CMS website. The exploit is triggered by sending a specially crafted HTTP request to the vulnerable website, which contains malicious SQL code. The malicious code is then executed by the vulnerable website, allowing the attacker to gain access to the admin panel.
Mitigation:
Ensure that all user-supplied input is properly sanitized and validated before being used in any SQL queries.