vendor:
Ultimate eShop
by:
Romka
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Ultimate eShop
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2011
Ultimate eShop Error Based SQL Injection Vulnerability
An attacker can exploit this vulnerability by sending a malicious payload to the vulnerable parameter 'go' in the URL. The payload 'ERROR BASED INJECTION' will cause an error in the application which will reveal the underlying database structure and allow the attacker to extract sensitive information.
Mitigation:
Input validation should be used to prevent SQL injection attacks. All user-supplied input should be validated and filtered before being used in SQL queries.