PT-2017-10066 · Moxa · Softcms

Gu Ziqiang

+1

·

Publicado

2017-02-13

·

Atualizado

2017-06-28

·

CVE-2016-9333

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moxa SoftCMS versions prior to 1.6
Description The issue allows a remote attacker to gain access with administrator privileges through specially crafted input, leveraging a SQL injection technique. This occurs because the SoftCMS Application does not properly sanitize input.
Recommendations For versions prior to 1.6, update to version 1.6 or later to resolve the issue.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9333

Produtos afetados

Softcms