header-logo
Suggest Exploit
vendor:
Xoops module Articles
by:
ajann
7.5
CVSS
HIGH
SQL Injection
CWE
Product Name: Xoops module Articles
Affected Version From: 01.02
Affected Version To: 01.02
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:

Xoops module Articles <= 1.02 (index.php cat_id) SQL Injection Exploit

The Xoops module Articles version 1.02 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by injecting malicious SQL queries in the 'cat_id' parameter of the 'index.php' file. This allows the attacker to retrieve sensitive information from the database, such as usernames and passwords of Xoops users.

Mitigation:

Update to a patched version of the Xoops module Articles (version 1.02 or higher).
Source

Exploit-DB raw data: