Family: CGI abuses --> Category: infos
Hosting Controller ForumID Parameter SQL Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Checks for a SQL injection flaw in Hosting Controller
Detailed Explanation for this Vulnerability Test
The remote web server contains an ASP application that is susceptible
to a SQL injection attack.
The installed version of Hosting Controller fails to sanitize input to
the 'ForumID' parameter of the 'forum/HCSpecific/EnableForum.asp'
script before using it in database queries. An unauthenticated
attacker may be able to leverage this issue to manipulate database
queries to reveal sensitive information, modify data, launch attacks
against the underlying database, etc.
See also :
Unknown at this time.
High / CVSS Base Score : 7
Click HERE for more information and discussions on this network vulnerability scan.