vendor:
Kasseler CMS
by:
S(r1pt - xaknet.ru
7,5
CVSS
HIGH
Readfile/XSS
200, 79
CWE
Product Name: Kasseler CMS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Kasseler-Cms (Reafile/XSS) Multiple Remote Vulnerabilities
Kasseler CMS is prone to multiple remote vulnerabilities, including a readfile vulnerability and a cross-site scripting vulnerability. An attacker can exploit these issues to read sensitive files from the server, or to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Mitigation:
Users should avoid following untrusted links and should never supply sensitive information to untrusted websites.