PT-2017-11818 · Finecms · Finecms

Lorexxar

·

Published

2017-07-13

·

Updated

2017-07-16

·

CVE-2017-11200

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FineCMS versions prior to 2017-07-12
Description A SQL Injection issue exists via the visitor ip parameter in the application/core/controller/excludes.php file.
Recommendations For FineCMS versions prior to 2017-07-12, avoid using the visitor ip parameter in the affected file until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11200

Affected Products

Finecms