vendor:
devalcms
by:
IRCRASH (R3d.W0rm (Sina Yazdanmehr))
9.3
CVSS
HIGH
Remote Code Execution / XSS
79
CWE
Product Name: devalcms
Affected Version From: v1.4a
Affected Version To: v1.4a
Patch Exists: YES
Related CWE: N/A
CPE: a:devalcms:devalcms:1.4a
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
devalcms v1.4a Remote Code Execution Exploit / Xss
A vulnerability exists in devalcms v1.4a which allows an attacker to execute arbitrary code on the vulnerable system. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious JavaScript code to the vulnerable application. This can be done by sending a malicious HTTP request to the vulnerable application with the ‘currentpath’ parameter set to a malicious JavaScript code.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of the application.