vendor:
WF-Links
by:
ajann
7.5
CVSS
HIGH
Remote Blind SQL Injection
CWE
Product Name: WF-Links
Affected Version From: 1.03 or below
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
XOOPS Module WF-Links <= 1.03 (cid) Remote BLIND SQL Injection Exploit
This exploit allows an attacker to perform a blind SQL injection attack in XOOPS Module WF-Links version 1.03 or below. The vulnerability allows the attacker to retrieve sensitive information from the database, such as usernames and passwords of the XOOPS users.
Mitigation:
Upgrade to a fixed version of XOOPS Module WF-Links (version > 1.03)