vendor:
Webmatic
by:
v3n0m
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Webmatic
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Webmatic (index.php) SQL Injection Vulnerability
An attacker can exploit this vulnerability by sending a crafted SQL query to the vulnerable application. The crafted query can be sent via the 'p' parameter in the 'index.php' script. The query will be executed in the context of the application and can be used to extract sensitive information from the database.
Mitigation:
Input validation should be used to prevent SQL injection attacks.