vendor:
AContent
by:
High-Tech Bridge Security Research Lab
7.57.54.3
CVSS
HIGH
SQL Injection [CWE-89], Improper Authentication [CWE-287], Cross-Site Scripting [CWE-79]
89, 287, 79
CWE
Product Name: AContent
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: YES
Related CWE: CVE-2012-5167, CVE-2012-5168, CVE-2012-5169
CPE: AContent
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
Advisory ID: HTB23117
High-Tech Bridge Security Research Lab discovered multiple vulnerabilities in AContent, which can be exploited to bypass authentication and to perform Cross-Site Scripting (XSS) and SQL Injection attacks. The vulnerability exists due to insufficient sanitation of input data in the 'field' HTTP POST parameter in /course_category/index_inline_editor_submit.php and /user/index_inline_editor_submit.php. A remote unauthenticated user can execute arbitrary SQL commands in application`s database.
Mitigation:
Fixed by Vendor