Description


A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

References


https://vuldb.com/?id.95407

Third Party AdvisoryVDB Entry

https://www.exploit-db.com/exploits/41044/

ExploitThird Party AdvisoryVDB Entry

Weaknesses



CWE-89


CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2022-06-21T06:15:07.117

3 years ago

Last modified

2022-06-28T18:43:23.917

3 years ago