vendor:
b2evolution
by:
High-Tech Bridge Security Research Lab
5,1
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: b2evolution
Affected Version From: 4.1.6
Affected Version To: 4.1.6
Patch Exists: YES
Related CWE: CVE-2013-2945
CPE: a:b2evolution_group:b2evolution
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
SQL Injection in b2evolution: CVE-2013-2945
High-Tech Bridge Security Research Lab discovered SQL injection vulnerability in b2evolution, which can be exploited to alter SQL requests passed to the vulnerable application's database. A remote authenticated administrator can execute arbitrary SQL commands in application's database. Depending on database and system configuration, PoC code below will create a "/tmp/file.txt" file, containing MySQL version. This vulnerability is also exploitable via CSRF vector, since the application is prone to Cross-Site Request Forgery (CSRF) attacks.
Mitigation:
Upgrade to b2evolution 4.1.7