vendor:
Asbru Web Content Management System
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Directory Traversal, Open Redirect, Cross-Site Request Forgery, Stored Cross-Site Scripting
22,601,352,79
CWE
Product Name: Asbru Web Content Management System
Affected Version From: 9.2.7
Affected Version To: 9.2.7
Patch Exists: YES
Related CWE: N/A
CPE: a:asbrusoft:asbru_web_content_management_system:9.2.7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache Tomcat/5.5.23, Apache/2.2.3 (CentOS)
2016
Asbru Web Content Management System v9.2.7 Multiple Vulnerabilities
Asbru WCM suffers from multiple vulnerabilities including Cross-Site Request Forgery, Stored Cross-Site Scripting, Open Redirect and Information Disclosure.
Mitigation:
Ensure that all user input is properly validated and sanitized. Implement a strong access control mechanism to prevent unauthorized access to sensitive data. Use a web application firewall to detect and block malicious requests.