vendor:
CMS Formulasi
by:
Sarahma Security
7,5
CVSS
HIGH
SQL Injection, XSS, CSRF
89, 79, 352
CWE
Product Name: CMS Formulasi
Affected Version From: 2.07
Affected Version To: 2.07
Patch Exists: NO
Related CWE: N/A
CPE: a:formulasi:cms_formulasi:2.07
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Win 7/Backtrack
2013
CMS Formulasi 2.07 Multiple Vulnerability
CMS Formulasi 2.07 is vulnerable to SQL Injection, XSS and CSRF. An attacker can exploit these vulnerabilities to gain access to sensitive information, execute malicious code and perform unauthorized actions.
Mitigation:
Input validation, CSRF tokens, Content Security Policy, X-XSS-Protection, X-Content-Type-Options