Arastta 1.1.5: SQL Injection

Posted by Curesec Research Team (CRT) on Dec 23

Security Advisory – Curesec Research Team

1. Introduction

Affected Product: Arastta 1.1.5
Fixed in: not fixed
Fixed Version Link: n/a
Vendor Website: http://arastta.org/
Vulnerability Type: SQL Injection
Remote Exploitable: Yes
Reported to vendor: 11/21/2015
Disclosed to public: 12/21/2015
Release mode: Full Disclosure
CVE: n/a
Credits Tim Coen of Curesec GmbH

2. Overview

Arastta is…