vendor:
EasyCreate
by:
Vulnerability Laboratory Research Team
8,3
CVSS
CRITICAL
SQL Injection, Cross Site Scripting, Local File Inclusion, Remote File Inclusion, Cross Site Request Forgery, Session Fixation, Session Hijacking, Security Bypass, Path Traversal, Denial of Service
89, 79, 22, 98, 352, 384, 613, 287, 22, 400
CWE
Product Name: EasyCreate
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:iscripts:easycreate
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web
2012
iScripts EasyCreate CMS v2.0 – Multiple Web Vulnerabilites
The Vulnerability Laboratory Research Team discovered multiple web vulnerabilites in iScripts EasyCreate v2.0 CMS. These vulnerabilities include SQL Injection, Cross Site Scripting, Local File Inclusion, Remote File Inclusion, Cross Site Request Forgery, Session Fixation, Session Hijacking, Security Bypass, Path Traversal, and Denial of Service.
Mitigation:
Ensure that all user input is properly sanitized and validated before being used in any SQL queries. Ensure that all user input is properly sanitized and validated before being used in any HTML output. Ensure that all user input is properly sanitized and validated before being used in any file operations. Ensure that all user input is properly sanitized and validated before being used in any HTTP requests. Ensure that all user input is properly sanitized and validated before being used in any session operations. Ensure that all user input is properly sanitized and validated before being used in any security operations. Ensure that all user input is properly sanitized and validated before being used in any file system operations. Ensure that all user input is properly sanitized and validated before being used in any DoS operations.