vendor:
Solutive CMS
by:
Th3 RDX
9,3
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Solutive CMS
Affected Version From: 1.0
Affected Version To: 1.2
Patch Exists: Yes
Related CWE: CVE-2010-4456
CPE: a:solutive:solutive_cms
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2010
Solutive CMS SQL Injection Vulnerability
Solutive CMS is vulnerable to SQL Injection. An attacker can inject malicious SQL queries via the 'id' parameter in the 'product_detail.php', 'news_content.php' and 'products_by_cat.php' scripts. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Mitigation:
Input validation and output encoding