vendor:
MyClassifieds
by:
SecurityFocus
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: MyClassifieds
Affected Version From: 2.11
Affected Version To: 2.11
Patch Exists: YES
Related CWE: N/A
CPE: a:fuzzymonkey:myclassifieds
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
SQL Injection Vulnerability in FuzzyMonkey MyClassifieds
It has been reported that FuzzyMonkey MyClassifieds may be prone to a SQL injection vulnerability that may allow an attacker to disclose user passwords by supplying malicious SQL code to the Email variable. This attack may cause the software to write user password to a world readable file, which may be accessed to launch further attacker against a system. A malicious user may influence database queries in order to view or modify sensitive information, and gain unauthorized access by disclosing user passwords therefore potentially compromising the software or the database.
Mitigation:
Input validation should be used to prevent malicious SQL code from being supplied to the Email variable.