vendor:
Ovidentia
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Ovidentia
Affected Version From: 7.9.4
Affected Version To: 7.9.4
Patch Exists: YES
Related CWE: N/A
CPE: a:cantico:ovidentia:7.9.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 7 Ultimate SP1 (EN), Apache 2.4.2 (Win32), PHP 5.4.7, MySQL 5.5.25a
2013
Ovidentia 7.9.4 Multiple Remote Vulnerabilities
Input passed via several parameters is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and HTML/script code in a user's browser session in context of an affected site.
Mitigation:
Input validation should be used to prevent the execution of malicious code.