vendor:
Netrix CMS
by:
Mr.tro0oqy
8,8
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: Netrix CMS
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: Yes
Related CWE: N/A
CPE: a:netrix:netrix_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Netrix CMS 1.0 (Auth Bypass) Remote SQL Injection Vulnerability
A vulnerability in Netrix CMS 1.0 allows an attacker to bypass authentication and gain access to the administrative panel. This is done by sending a crafted HTTP request to cikkform.php with the parameter cid set to 1. This will allow the attacker to gain access to the administrative panel and edit anything or put on their own index.
Mitigation:
Upgrade to the latest version of Netrix CMS 1.0