vendor:
aMSN
by:
drone (@dronesec)
7,5
CVSS
HIGH
Local File Inclusion/SQL Injection
89
CWE
Product Name: aMSN
Affected Version From: 0.98.9
Affected Version To: 0.98.9
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 12.04 (apparmor disabled)
2013
aMSN LFI/SQLi
Preauth LFI and SQLi in the web app packaged with aMSN 0.98.9
Mitigation:
SVN repositories (r12422)