vendor:
Koobi CMS
by:
JosS
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Koobi CMS
Affected Version From: 4.3.2000
Affected Version To: 4.2.2004
Patch Exists: YES
Related CWE: N/A
CPE: a:dream4:koobi_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Koobi CMS 4.3.0, 4.2.5, 4.2.4 Multiple Remote SQL Injection
Koobi CMS versions 4.3.0, 4.2.5, and 4.2.4 are vulnerable to multiple remote SQL injection attacks. An attacker can exploit this vulnerability to gain access to the admin data, such as email and password, by sending a malicious SQL query to the vulnerable parameter. The vulnerable parameters are 'galid' in the 'gallery' module, 'categ' in the 'links' and 'downloads' modules.
Mitigation:
Upgrade to the latest version of Koobi CMS.