vendor:
Multiple Products by Web Wiz
by:
devil_box
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Multiple Products by Web Wiz
Affected Version From: Web Wiz Site News 3.06 for Access 2000 and Access 97, Web Wiz Journal 1.0 for Access 2000 and Access 97, Web Wiz Polls 3.06 for Access 2000 and Access 97, Web Wiz Database Login 1.71 for Access 2000 and Access 97
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:web_wiz:site_news:3.06, cpe:/a:web_wiz:journal:1.0, cpe:/a:web_wiz:polls:3.06, cpe:/a:web_wiz:database_login:1.71
Platforms Tested:
SQL injection vulnerability in Multiple Products by Web Wiz
The vulnerability allows an attacker to bypass authentication and gain unauthorized access to a site. It can also lead to disclosure or modification of data and exploitation of vulnerabilities in the underlying database implementation.
Mitigation:
Implement proper input validation and parameterized queries to prevent SQL injection attacks.