vendor:
Clicker CMS
by:
hacker@sr.gov.yu
7,5
CVSS
HIGH
Blind Sql Injection
89
CWE
Product Name: Clicker CMS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows & Linux
2010
Clicker CMS Blind SQL Injection Vulnerability
It was found that Clicker CMS does not validate properly the 'lang' parameter value. An attacker can inject malicious SQL code into the 'lang' parameter value and execute it in the backend database.
Mitigation:
Input validation of 'lang' parameter should be corrected.