PT-2022-12030 · Oracle · Mysql Server
Caso
+1
·
Published
2022-01-28
·
Updated
2022-02-02
·
CVE-2021-44249
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Online Motorcycle (Bike) Rental System version 1.0
Description
The issue allows attackers to perform a Blind Time-Based SQL Injection attack within the login portal, potentially leading to the remote dumping of MySQL database credentials.
Recommendations
For Online Motorcycle (Bike) Rental System version 1.0, consider disabling the login portal functionality until a patch is available to prevent exploitation of the Blind Time-Based SQL Injection vulnerability. Restrict access to the MySQL database credentials to minimize the risk of unauthorized access.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mysql Server