vendor:
phpwebthing
by:
Qptan & AhLam
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: phpwebthing
Affected Version From: 1.4.2004
Affected Version To: 1.4.2004
Patch Exists: YES
Related CWE: N/A
CPE: a:phpwebthing:phpwebthing:1.4.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2005
SQL injection in phpwebthing v 1.4.4
This exploit allows an attacker to inject malicious SQL queries into the vulnerable application. The exploit is coded in Perl and is used to retrieve the MD5 hash of the password of a given user ID from the phpwebthing v 1.4.4 application.
Mitigation:
Input validation should be used to prevent SQL injection attacks.