vendor:
Fatwire Content Server
by:
J. Francisco Bolivar
8,8
CVSS
HIGH
XSS, Path Traversal, Blind SQL Injection
79, 22, 89
CWE
Product Name: Fatwire Content Server
Affected Version From: 6.3
Affected Version To: 6.3
Patch Exists: YES
Related CWE: N/A
CPE: oracle:fatwire_content_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: CentOS
2021
Oracle Fatwire 6.3 – Multiple Vulnerabilities
Adt parameter is vulnerable to XSS, Path traversal vulnerability can be exploited by accessing the URL with '../' and Blind SQL injection can be exploited by sending a malicious payload in the POST request.
Mitigation:
Input validation, Access control, Parameterized queries