Meneame English Pligg SQL Injection Vulnerability
Vulnerability
An SQL injection vulnerability has been identified in Meneame English Pligg version 5.8. This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious payloads through the search parameter. Exploitation involves sending GET requests to index.php with crafted SQL that can extract sensitive database information such as usernames, database names, and version details.
Impact
Exploitation of this vulnerability allows for arbitrary SQL execution, which could lead to unauthorized data access or manipulation within the database.
Reproduction
To reproduce this vulnerability, send a GET request to index.php with a crafted SQL payload in the search parameter. The SQL injection can be verified by extracting database information such as usernames and version details.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
