vendor:
xBtiTracker
by:
InATeam
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: xBtiTracker
Affected Version From: xbtit v.2.0.0 - revision 559
Affected Version To: xbtit v.2.0.0 - revision 559
Patch Exists: NO
Related CWE: N/A
CPE: 2.0.0-559
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: xbtit v.2.0.0 - revision 559
2010
xBtiTracker Remote SQL Injection Vulnerability
This exploit allows an attacker to inject malicious SQL code into the xBtiTracker application, which can be used to gain access to the application's database and potentially gain access to sensitive information.
Mitigation:
Ensure that all user-supplied input is properly sanitized and validated before being used in SQL queries.