vendor:
Webring service
by:
L0rd CrusAd3r
7,5
CVSS
HIGH
SQLi Vulnerability
89
CWE
Product Name: Webring service
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
The webring service SQL Injection
The Webring service offers a place where users can create their own webrings, which is a community of websites that are connected that offers more traffic to the member of the ring. With our webring service users easily create their free webring that also displays on the web site homepage, plus visitors the the users webrings can easily add their own website that is 100% moderated from the members area. This website has enormous traffic potential and features a rotating banners system and newsletter for advertising revenue.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.