vendor:
TOKOKITA Web Application
by:
k1tk4t
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: TOKOKITA Web Application
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
TOKOKITA Multiple Remote SQL Injection
A vulnerability in the TOKOKITA web application allows an attacker to inject arbitrary SQL commands into the application. This can be exploited to gain access to the application's database and potentially gain access to sensitive information. The vulnerability exists in the 'catlist.php', 'catlist_detail.php' and 'barang.php' scripts, where user-supplied input is not properly sanitized before being used in an SQL query. This can be exploited to inject arbitrary SQL commands which will be executed in the context of the database user.
Mitigation:
The vendor has released a patch to address this issue. It is recommended that users upgrade to the latest version of the application.