← volver
CVE-2018-25199

OOP CMS BLOG 1.0 SQL Injection via search parameter

CVSS 8.8 HIGHEPSS 0.4%CWE-89
OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameters. Attackers can inject SQL commands via the search parameter in search.php, pageid parameter in page.php, and id parameter in posts.php to extract database information including table names, schema names, and database credentials.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
Zsoft · OOP CMS BLOG

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →