Title: itMedia Multiple SQL Injection Vulnerabilities
Severity: MODERATE
Description:
itMedia is a web-based application implemented in PHP.
The application is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data to the 'op' parameter of the 'galerija.php', 'ponuda.php', and 'slike.php' scripts before using it in an SQL query. The 'id' parameter of the 'vijest.php' and 'vijesti.php' scripts is also used in an SQL query without being sufficiently sanitized.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Affected Products:
- itMedia itMedia
References:
- itMedia: itMedia Homepage
