vendor:
Yamamah
by:
anT!-Tr0J4n
8,8
CVSS
HIGH
SQL Injection / disclosure Vulnerability
89
CWE
Product Name: Yamamah
Affected Version From: 1.00
Affected Version To: 1.00
Patch Exists: NO
Related CWE: N/A
CPE: a:yamamah:yamamah:1.00
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Win7/Linux
2010
Yamamah Vulnerability (news) SQL Injection / disclosure Vulnerability
Yamamah source code disclosure Vulnerability can be exploited by sending a malicious HTTP request to the vulnerable server. Blind SQL Injection can be exploited by sending a malicious HTTP request to the vulnerable server with a crafted payload.
Mitigation:
Input validation, parameterized queries, and stored procedures should be used to prevent SQL injection attacks.