vendor:
Facil-CMS
by:
any.zicky
7.5
CVSS
HIGH
Multiple vulnerabilities
200, 287, 89
CWE
Product Name: Facil-CMS
Affected Version From: 0.1RC2
Affected Version To: 0.1RC2
Patch Exists: NO
Related CWE:
CPE: a:facilcms:facil-cms:0.1rc2
Platforms Tested:
2008
Facil-CMS 0.1RC2
The Facil-CMS 0.1RC2 has multiple vulnerabilities including PHPinfo disclosure, authentication bypass, and SQL injection in the News module.
Mitigation:
Apply the latest patch or upgrade to a newer version of Facil-CMS.