vendor:
Academic Web Tools CMS
by:
AmnPardaz Security Research Team
5.5
CVSS
MEDIUM
Directory Traversal, SQL Injection, Cross Site Scripting (XSS), Session Management Flaw
N/A
CWE
Product Name: Academic Web Tools CMS
Affected Version From: 1.4.2.8
Affected Version To: Prior Versions
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
N/A
Academic Web Tools CMS Multiple Vulnerabilities
ACADEMIC WEB TOOLS (AWT) yektaweb is a Persian content management system (CMS) which can manage university conferences and journals too. Directory Traversal in "/download.php" in "dfile" parameter, SQL Injection in "/rating.php" in "book_id" parameter, Reflected XSS attack in "/login.php" in URL parameters, Reflected XSS attack in "/hta/htmlarea.js.php" in "glb_sid" parameters, Reflected redirect XSS attack in "/rss_getfile.php" in "file" parameters, Stored XSS attack in "/room.php" chat service and Session Management Flaw in "/homepg/index.php" and "/homepg/login.php" are vulnerable to session fixation.
Mitigation:
N/A