Description


A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

References


https://vuldb.com/?id.95407

Third Party AdvisoryVDB Entry

https://www.exploit-db.com/exploits/41044/

ExploitThird Party AdvisoryVDB Entry

https://vuldb.com/?id.95407

Third Party AdvisoryVDB Entry

https://www.exploit-db.com/exploits/41044/

ExploitThird Party AdvisoryVDB Entry

Weaknesses



CWE-89


CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

7.3 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-06-21T04:15:07.117Z

3 years ago

Last modified

2024-11-21T02:22:33.690Z

1 year ago