vendor:
CMSBuzz
by:
Security Fears Team
5.5
CVSS
MEDIUM
Remote SQL Injection
89
CWE
Product Name: CMSBuzz
Affected Version From: 1
Affected Version To: 1.2
Patch Exists: YES
Related CWE: CVE-2018-19072
CPE: a:cmsbuzz:cmsbuzz:1.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2018
rEm0te sql injction VulnErability (cmsbuzz script)
CMSBuzz is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. An attacker can exploit this vulnerability to manipulate SQL queries by injecting arbitrary SQL code.
Mitigation:
Upgrade to the latest version of CMSBuzz