PT-2022-12030 · Oracle · Mysql Server

Caso

+1

·

Published

2022-01-28

·

Updated

2022-02-02

·

CVE-2021-44249

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Online Motorcycle (Bike) Rental System version 1.0
Description The issue allows attackers to perform a Blind Time-Based SQL Injection attack within the login portal, potentially leading to the remote dumping of MySQL database credentials.
Recommendations For Online Motorcycle (Bike) Rental System version 1.0, consider disabling the login portal functionality until a patch is available to prevent exploitation of the Blind Time-Based SQL Injection vulnerability. Restrict access to the MySQL database credentials to minimize the risk of unauthorized access.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44249

Affected Products

Mysql Server