vendor:
Cotonti CMS
by:
LiquidWorm and badc0re
7.5
CVSS
HIGH
SQL Injection and XSS
89
CWE
Product Name: Cotonti CMS
Affected Version From: 2000.9.4
Affected Version To: 2000.9.4
Patch Exists: YES
Related CWE: N/A
CPE: a:cotonti_team:cotonti:0.9.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 7 Ultimate SP1 (EN), Microsoft Windows XP Professional SP3 (EN), Apache 2.2.14 (Win32), PHP 5.3.1, MySQL 5.1.41
2011
Cotonti CMS v0.9.4 Multiple Remote Vulnerabilities
Input passed via the parameters 'redirect.php' in 'message.php' and 'w' and 'd' in 'index.php' script are not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code or execute arbitrary HTML and script code in a user's browser session in context of an affected site. Path disclosure resides in the 'sq' parameter in '/plugins/search/search.php' script.
Mitigation:
Upgrade to the latest version of Cotonti CMS