vendor:
AuraCMS
by:
Mustafa ALTINKAYNAK
8,8
CVSS
HIGH
Reflected XSS & LFI
79, 98
CWE
Product Name: AuraCMS
Affected Version From: 3.0
Affected Version To: 3.0
Patch Exists: NO
Related CWE: N/A
CPE: a:auracms:auracms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: XAMP on Windows 8
2014
AuraCMS 3.0 Multiple Vulnerabilities
AuraCMS 3.0 is vulnerable to Reflected XSS and LFI. The FileManager parameter is unfiltered and can be used to inject malicious code. Directory listing is also possible.
Mitigation:
Not published.