PT-2017-14311 · D Park Pro · D-Park Pro Domain Parking Script

Ihsan Sencan

·

Published

2017-10-29

·

Updated

2017-11-17

·

CVE-2017-15958

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Park Pro Domain Parking Script version 1.0
Description The issue allows SQL Injection via the username to "admin/loginform.php".
Recommendations For D-Park Pro Domain Parking Script version 1.0, update the script to properly sanitize user input, specifically the username variable, to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15958

Affected Products

D-Park Pro Domain Parking Script