vendor:
Quate CMS
by:
Digital Security Research Group [DSecRG]
7.5
CVSS
HIGH
RFI, Multiple LFI, Directory traversal, Multiple XSS
94, 79, 22, 78
CWE
Product Name: Quate CMS
Affected Version From: 2000.3.4
Affected Version To: 2000.3.4
Patch Exists: NO
Related CWE: N/A
CPE: a:quate:quate_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
DSECRG-08-030
Quate CMS system has multiple security vulnerabilities: 1. Multiple Remote/Local File Include, 2. Multiple Linked XSS vulnerabilities, 3. Directory traversal. Quate CMS has Multiple Local File Include vulnerabilities. Local File Include vulnerability found in script admin/includes/footer.php. Remote and Local File Include vulnerability found in script admin/includes/header.php. Multiple Linked XSS vulnerabilities found in script admin/includes/header.php. Directory traversal vulnerability found in script admin/includes/header.php.
Mitigation:
Update to the latest version of Quate CMS.