vendor:
Tr Forum
by:
DarkFig
5,5
CVSS
MEDIUM
SQL Injection, Bypass Security Restriction
N/A
CWE
Product Name: Tr Forum
Affected Version From: V2.0
Affected Version To: V2.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Tr Forum V2.0 Admin MD5 Passwd Hash Disclosure
This exploit allows an attacker to bypass security restrictions and gain access to the admin panel of Tr Forum V2.0. The attacker can then obtain the MD5 password hash of the admin user.
Mitigation:
Ensure that all user input is properly sanitized and validated before being used in SQL queries.