vendor:
Netious CMS
by:
InjEctOr [s0f (at) w (dot) cn] && ToTaL [n.47 at hotmail.com]
9.3
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Netious CMS
Affected Version From: 0.4
Affected Version To: 0.4
Patch Exists: YES
Related CWE: CVE-2008-4456
CPE: a:netious:netious_cms
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1289/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0110/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1461/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2008-4456/, https://www.rapid7.com/db/vulnerabilities/apple-osx-mysql-cve-2008-4456/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2008-4456/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2008-4456/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2008
Netious CMS 0.4 Remote SQL Injection Vulnerability
Netious CMS 0.4 is prone to a remote SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied data before using it in an SQL query. An attacker can exploit this issue to manipulate SQL queries by injecting arbitrary SQL code. This may allow the attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Mitigation:
Upgrade to the latest version of Netious CMS 0.4