vendor:
1024cms
by:
Unknown
7.5
CVSS
HIGH
Cross-site scripting, Local file-include, Directory-traversal
79, 98, 22
CWE
Product Name: 1024cms
Affected Version From: 1.1.0 beta
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:1024cms:1024cms:1.1.0
Platforms Tested:
Unknown
Multiple vulnerabilities in 1024cms
The 1024cms application is prone to multiple cross-site scripting vulnerabilities, multiple local file-include vulnerabilities, and a directory-traversal vulnerability. An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser, steal authentication credentials, and access sensitive information.
Mitigation:
Apply the latest security patches and updates provided by the vendor. Implement input validation and sanitization techniques to prevent cross-site scripting and directory-traversal attacks.