vendor:
Ripe Website Manager
by:
John Martinelli
7.5
CVSS
HIGH
Cross-Site Scripting and SQL Injection
79
CWE
Product Name: Ripe Website Manager
Affected Version From: 2000.8.4
Affected Version To: 2000.8.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Ripe Website Manager (<= 0.8.4) - Cross-Site Scripting and SQL Injection Exploit
This exploit allows an attacker to perform cross-site scripting and SQL injection attacks in Ripe Website Manager version 0.8.4 and below. The exploit was discovered by John Martinelli.
Mitigation:
To mitigate this vulnerability, it is recommended to update Ripe Website Manager to a version higher than 0.8.4.