vendor:
PlexusCMS
by:
neglomaniac
8,8
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: PlexusCMS
Affected Version From: 0.5
Affected Version To: 0.5
Patch Exists: No
Related CWE: N/A
CPE: cpe:a:plexus_cms:plexus_cms:0.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
plexusCMS 0.5 XSS Remote Shell Exploit
This exploit allows an attacker to upload a malicious file to a vulnerable PlexusCMS 0.5 installation. The attacker can then use XSS and social engineering techniques to get the victim to open a malicious URL, which will execute the malicious file.
Mitigation:
Ensure that all user-supplied input is properly sanitized and validated before being used.