vendor:
CMS
by:
41.w4r10r aka AN1L
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: CMS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache/Unix
2010
Worldviewer.com CMS SQL Injection Vulnerability
This is a vulnerability in the CMS created by the leading web development company Worldviewer.com. It allows attackers to inject malicious SQL code into vulnerable parameters in the URL. This can be exploited to gain access to the database and potentially sensitive information.
Mitigation:
Input validation should be used to prevent malicious SQL code from being injected into vulnerable parameters in the URL.