vendor:
NULL NUKE CMS
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
SQL Injection, CSRF, Stored XSS, Arbitrary File Upload, RCE, Arbitrary File Deletion, Arbitrary File Access, Open Redirection, Parameter Traversal
89, 79, 78, 77, 22, 20, 16, 6, 4
CWE
Product Name: NULL NUKE CMS
Affected Version From: 2.2
Affected Version To: 2.1 rc3
Patch Exists: YES
Related CWE: N/A
CPE: a:nullwanton:null_nuke_cms:2.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache/2.4.7 (Win32), PHP/5.5.6, MySQL 5.6.14
2014
NULL NUKE CMS v2.2 Multiple Vulnerabilities
NULL NUKE CMS suffers from multiple remote vulnerabilities including Stored/Reflected XSS, SQL Injection, Arbitrary File Upload, RCE, Arbitrary File Deletion, Arbitrary File Access using absolute path and/or traversal, Open Redirection, Parameter Traversal, and Cross-Site Request Forgery.
Mitigation:
Ensure that all user input is properly sanitized and validated. Ensure that all user input is properly escaped. Ensure that all user input is properly encoded. Ensure that all user input is properly filtered. Ensure that all user input is properly validated. Ensure that all user input is properly authenticated. Ensure that all user input is properly authorized. Ensure that all user input is properly secured.