vendor:
TR Forum 1.5
by:
indoushka
8,8
CVSS
HIGH
Multiple Vulnerabilities
89, 79, 200
CWE
Product Name: TR Forum 1.5
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: NO
Related CWE: N/A
CPE: a:tr_forum:tr_forum:1.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2008
TR Forum 1.5 Mullti Vulnerability
TR Forum 1.5 is vulnerable to SQL injection, XSS and reinstallation of admin information. An attacker can exploit these vulnerabilities by sending a malicious SQL query to the application, injecting malicious JavaScript code into the application or reinstalling the admin information.
Mitigation:
Input validation, sanitization and proper authentication should be implemented to prevent these vulnerabilities.