vendor:
Traidnt UP v2.0
by:
Jafer Al-Zidjali
N/A
CVSS
N/A
SQL Injection Vulnerability
CWE
Product Name: Traidnt UP v2.0
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2009
Traidnt UP v2.0 Exploit
This is an exploit for the Traidnt UP v2.0 script that allows for SQL injection. The exploit was discovered and written by Jafer Al-Zidjali. The vulnerability occurs when the magic_quotes_gpc setting is turned off. The author has been notified and a public patch has been released for this vulnerability.
Mitigation:
Ensure that the magic_quotes_gpc setting is enabled to prevent SQL injection attacks. Apply the public patch that has been released for this vulnerability.