vendor:
CafeEngine CMS
by:
Sid3^effects aKa HaRi
7,4
CVSS
HIGH
SQL Injection
89
CWE
Product Name: CafeEngine CMS
Affected Version From: 2.3
Affected Version To: 2.3
Patch Exists: YES
Related CWE: CVE-2010-2245
CPE: a:cafeengine:cafeengine_cms:2.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2010
CafeEngine CMS V2.3 SQLI Vulnerability
CafeEngine CMS V2.3 is vulnerable to SQL injection. Attackers can exploit this vulnerability to gain access to the database and execute arbitrary SQL commands. This vulnerability is due to the lack of input validation in the "search.php" script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious SQL statements to the vulnerable script.
Mitigation:
Upgrade to the latest version of CafeEngine CMS.