vendor:
Admidio
by:
Stefan Schurtz
N/A
CVSS
N/A
XSS and SQLi
Not mentioned
CWE
Product Name: Admidio
Affected Version From: 2.3.2005
Affected Version To: 2.3.2006
Patch Exists: YES
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Not mentioned
2012
Admidio 2.3.5 Multiple security vulnerabilities
Admidio 2.3.5 is prone to XSS and SQLi vulnerabilities. The SQLi vulnerability can be exploited by sending a malicious request to 'adm_program/modules/lists/lists.php?active_role=' parameter. The XSS vulnerability can be exploited by injecting a script in the 'headline' parameter of 'adm_program/modules/guestbook/guestbook_new.php'.
Mitigation:
Upgrade to the latest version 2.3.6