vendor:
GENU CMS
by:
Vulnerability Laboratory Research Team
9
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: GENU CMS
Affected Version From: GENU CMS 2012.3
Affected Version To: GENU CMS 2012.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP, MySQL, PostgreSQL or SQLite
2012
GENU CMS 2012.3 – Multiple SQL Injection Vulnerabilities
A SQL Injection vulnerability is detected in GENU CMS 2012.3. The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms. Successful exploitation of the vulnerability results in dbms & application compromise.
Mitigation:
Update to the latest version (GENU CMS 2012.4)