vendor:
PolyPager
by:
CWH Underground
7.5
CVSS
HIGH
SQL/XSS
89, 79
CWE
Product Name: PolyPager
Affected Version From: <= 1.0rc2
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: a:nicolashoening:polypager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
PolyPager <= 1.0rc2 (SQL/XSS) Multiple Remote Vulnerabilities
PolyPager <= 1.0rc2 is vulnerable to multiple remote vulnerabilities. The first vulnerability is a SQL injection vulnerability which allows an attacker to dump username and password in clear text. The second vulnerability is a XSS vulnerability which allows an attacker to inject malicious JavaScript code.
Mitigation:
Upgrade to the latest version of PolyPager.