vendor:
Xoops module Articles
by:
ajann
7.5
CVSS
HIGH
SQL Injection
CWE
Product Name: Xoops module Articles
Affected Version From: 01.02
Affected Version To: 01.02
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Xoops module Articles <= 1.02 (index.php cat_id) SQL Injection Exploit
The Xoops module Articles version 1.02 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by injecting malicious SQL queries in the 'cat_id' parameter of the 'index.php' file. This allows the attacker to retrieve sensitive information from the database, such as usernames and passwords of Xoops users.
Mitigation:
Update to a patched version of the Xoops module Articles (version 1.02 or higher).