vendor:
Storyteller CMS System
by:
Shamus
N/A
CVSS
N/A
SQL Injection
89
CWE
Product Name: Storyteller CMS System
Affected Version From: 1.8
Affected Version To: 1.8
Patch Exists: NO
Related CWE: N/A
CPE: a:esselbach:storyteller_cms_system
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2011
Esselbach Storyteller CMS System Version 1.8 [page.php] Remote SQL Injection Vulnerability
A weakness has been discovered in Esselbach Storyteller CMS System Version 1.8, where an attacker may execute arbitrary SQL statements on the vulnerable system. This may compromise the integrity of the database and/or expose sensitive information. This vulnerability is identified in the path 'page.php'.
Mitigation:
Filter metacharacters from user inputs.