vendor:
Content-Builder (CMS)
by:
Federico Fazzi
7,5
CVSS
HIGH
Remote command execution
N/A
CWE
Product Name: Content-Builder (CMS)
Affected Version From: 0.7.5
Affected Version To: 0.7.5
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Content-Builder (CMS) 0.7.5, Remote command execution
Multiple vulnerabilities exist in Content-Builder (CMS) 0.7.5, which can be exploited by malicious people to conduct unauthorized activities. The vulnerabilities are caused due to the use of user-supplied input in several scripts without proper sanitization. This can be exploited to execute arbitrary commands by e.g. passing malicious parameters to the vulnerable scripts. Successful exploitation requires that the attacker can access the vulnerable scripts directly.
Mitigation:
Unavailable