vendor:
XOOPS Module Tutoriais
by:
ajann
7.5
CVSS
HIGH
Remote SQL Injection
CWE
Product Name: XOOPS Module Tutoriais
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
XOOPS Module Tutoriais (viewcat.php) Remote BLIND SQL Injection Exploit
This exploit allows an attacker to perform a blind SQL injection attack on the XOOPS Module Tutoriais (viewcat.php) script. By manipulating the 'cid' parameter, an attacker can retrieve sensitive information from the database, such as usernames and passwords of the XOOPS users.
Mitigation:
Update to a patched version of the XOOPS Module Tutoriais module or apply proper input validation to prevent SQL injection attacks.