vendor:
myAlbum-P module
by:
ajann
7.5
CVSS
HIGH
BLIND SQL Injection
Not mentioned
CWE
Product Name: myAlbum-P module
Affected Version From: 2.0 or earlier
Affected Version To: 2
Patch Exists: NO
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Not mentioned
Not mentioned
XOOPS Module myAlbum-P <= 2.0 (cid) Remote BLIND SQL Injection Exploit
This exploit allows an attacker to perform a blind SQL injection attack in the myAlbum-P module of XOOPS CMS version 2.0 or earlier. By manipulating the 'cid' parameter in the viewcat.php file, an attacker can extract sensitive information from the database.
Mitigation:
Upgrade to a newer version of the myAlbum-P module that is not vulnerable to SQL injection attacks. Alternatively, sanitize user input before using it in database queries.