Family: CGI abuses --> Category: attack
OrangeHRM txtUserName SQL Injection Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Tries to bypass OrangeHRM's authentication
Detailed Explanation for this Vulnerability Test
The remote web server contains a PHP script that is affected by a SQL
The remote host is running OrangeHRM, a human resource management
system written in PHP.
The version of OrangeHRM installed on the remote host fails to
sanitize input to the 'txtUserName' parameter of the 'login.php'
script before using it in a database query. An unauthenticated remote
attacker may be able to leverage this flaw to manipulate SQL queries
and, for example, bypass authentication, uncover sensitive
information, modify data, or even launch attacks against the
Note that successful exploitation of this issue requires that PHP's
'magic_quotes_gpc' be disabled.
See also :
Upgrade to OrangeHRM 2.1 alpha 5 or later.
Medium / CVSS Base Score : 5.6
Click HERE for more information and discussions on this network vulnerability scan.