What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.
Explanation of Vulnerability in Simple Terms
Sayfa Sayac version 2.6 and earlier contains a SQL injection vulnerability accessible over the network without authentication. An attacker can craft malicious input to execute arbitrary SQL queries, potentially reading sensitive data from the database or disrupting site availability. The vulnerability requires no user interaction and affects the confidentiality and availability of the affected system.
What an attacker can do
Execute SQL queries to read database contents or cause the site to become unavailable.
Potential impact on your site
Attackers can steal sensitive data from your database or disrupt your site's availability without needing a user account.
Conditions required to exploit
Network access to the vulnerable application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities