ExoPHPDesk.faq.php.Remote.SQL.Injection

description-logoDescription

It indicates a possible exploit of a SQL injection vulnerability in ExoPHPDesk.
This flaw is due to an input validation error in the "kb_view_in()" [class/kb.php] function (called via "faq.php") that does not validate the "id" parameter before it is used in SQL statements, which could be exploited by malicious users to conduct SQL injection attacks.

affected-products-logoAffected Products

EXO PHPDesk version 1.2.1 and prior.

Impact logoImpact

The execution of arbitrary SQL commands on the system.

recomended-action-logoRecommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)