PT-2014-4915 · Cis · Cis Manager Cms

Publicado

2014-04-11

·

Atualizado

2014-04-14

·

CVE-2014-2847

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CIS Manager CMS (affected versions not specified)
Description A SQL injection issue exists in the default.asp file of CIS Manager CMS, allowing remote attackers to execute arbitrary SQL commands by manipulating the TroncoID parameter in the vulnerable API endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-2847

Produtos afetados

Cis Manager Cms