vendor:
Acidcat CMS
by:
LionTurk
8,8
CVSS
HIGH
Multiple Vulnerabilities
N/A
CWE
Product Name: Acidcat CMS
Affected Version From: 3.5
Affected Version To: 3.5.1.f
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Acidcat CMS v 3.5 Multi Vulnerability
The Acidcat CMS v 3.5 is vulnerable to multiple vulnerabilities, including directory traversal, SQL injection, and remote file inclusion. The vulnerable URLs are http://server/[dizin]/databases/acidcat_3.mdb and http://server/[dizin]/install.asp. The script is powered by Acidcat CMS v 3.5.1.f.
Mitigation:
Apply the latest security patches and ensure that all web applications are up to date.