vendor:
Siteman
by:
IRCRASH (Dr.Crash Or Khashayar Fereidani)
7.5
CVSS
HIGH
Multiple Remote Vulnerabilities (CODE EXECUTION/LFI/XSS)
CWE
Product Name: Siteman
Affected Version From: Siteman 2.0.x2
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Siteman 2.X (0Day)
The Siteman 2.X application is affected by multiple vulnerabilities including code execution, local file inclusion (LFI), and cross-site scripting (XSS). The code execution vulnerability allows an attacker to execute arbitrary code on the server. The LFI vulnerability allows an attacker to read files on the server. The XSS vulnerability allows an attacker to inject malicious code into the application. These vulnerabilities can be exploited remotely.
Mitigation:
To mitigate these vulnerabilities, it is recommended to update to the latest version of Siteman and implement proper input validation and output encoding in the application.