vendor:
SweetRice CMS
by:
High-Tech Bridge SA - Ethical Hacking & Penetration Testing
3.3
CVSS
LOW
Logic error, XSS (Cross Site Scripting), SQL Injection
CWE
Product Name: SweetRice CMS
Affected Version From: 2000.6.7
Affected Version To:
Patch Exists: YES (XSS), NO (Logic error, SQL Injection)
Related CWE:
CPE:
Platforms Tested:
2010
SweetRice CMS Vulnerabilities
The logic error vulnerability allows an attacker to change the admin password by exploiting the '/as/index.php' script. The XSS vulnerability allows an attacker to execute malicious scripts by injecting them into the 'username' variable from a cookie. The SQL injection vulnerability allows an attacker to manipulate the SQL queries in the '/as/index.php' script.
Mitigation:
Upgrade to the most recent version