vendor:
.NET
by:
7.5
CVSS
HIGH
Cross-Site Scripting (XSS), SQL Injection, Information Disclosure
79, 89, 200
CWE
Product Name: .NET
Affected Version From: 5.1
Affected Version To: 5.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Multiple Remote Vulnerabilities in Absolute News Manager .NET
Attackers can exploit these issues to steal cookie-based authentication credentials, execute arbitrary script code in the context of the webserver process, obtain sensitive information, access or modify data, or exploit latent vulnerabilities in the underlying database.
Mitigation:
Apply patches provided by the vendor.