vendor:
XOOPS Module Repository
by:
ajann
5.5
CVSS
MEDIUM
Blind SQL Injection
89
CWE
Product Name: XOOPS Module Repository
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
XOOPS Module Repository (viewcat.php) BLIND SQL Injection Exploit
This exploit takes advantage of a blind SQL injection vulnerability in the XOOPS Module Repository viewcat.php script. It allows an attacker to extract the username and password hashes from the xoops_users table.
Mitigation:
Apply the latest security patches or updates provided by the vendor. Avoid using vulnerable versions of the XOOPS Module Repository module.