vendor:
leaftec cms
by:
Valentin Höbel
5.5
CVSS
MEDIUM
Multiple vulnerabilities
CWE
Product Name: leaftec cms
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Debian etch
2010
leaftec cms multiple vulnerabilities
The leaftec cms is vulnerable to SQL Injection and XSS/HTML Code Injection. The SQL Injection vulnerability can be exploited by manipulating the 'id' parameter in the 'article.php' file. The XSS/HTML Code Injection vulnerability allows an attacker to inject malicious HTML or JavaScript code, which is then executed on the website. Examples of both vulnerabilities are provided in the text.
Mitigation:
Upgrade to version XX or higher if available.