vendor:
web2Project
by:
High-Tech Bridge Security Research Lab
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: web2Project
Affected Version From: 3.1
Affected Version To: 3.1
Patch Exists: YES
Related CWE: CVE-2014-3119
CPE: web2Project
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
SQL Injection in web2Project: CVE-2014-3119
A remote authenticated user with privileges to access 'contacts' module can inject and execute arbitrary SQL commands in application’s database and e.g. create, alter and delete information, or gain unauthorized access to vulnerable website. A remote unauthenticated attacker can inject and execute arbitrary SQL commands in application’s database and e.g. create, alter and delete information, or gain unauthorized access to vulnerable website.
Mitigation:
Fixed by Vendor