vendor:
Realm CMS
by:
AmnPardaz Security Research Team
7.5
CVSS
HIGH
Broken Authentication and Session Management, Injection Flaws, Cross Site Scripting (XSS), Information Leakage
CWE
Product Name: Realm CMS
Affected Version From: 2.3 and prior versions
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Realm CMS Multiple Vulnerabilities Lead to Admin Access
Attacker can enter to the admin pages by a manipulated cookie. SQL Injection in 'inc_routines.asp' in 'KeyWordsList' function on 'kwrd' parameter. Reflected XSS attack, and DB path disclosure in '/cms/_db/compact.asp'