vendor:
ProjectCMS
by:
Juan Galiana Lara
9
CVSS
HIGH
SQL INJECTION (SQLi)
89
CWE
Product Name: ProjectCMS
Affected Version From: 1.0 Beta Final
Affected Version To: 1.0 Beta Final
Patch Exists: YES
Related CWE: CVE-2009-4010
CPE: a:projectcms:projectcms:1.0_beta_final
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2009
SQL INJECTION (SQLi) VULNERABILITY
ProjectCMS v1.0 Beta Final is vulnerable to SQL injection. Attackers can exploit this vulnerability to gain access to the database and execute arbitrary SQL commands.
Mitigation:
Upgrade to the latest version of ProjectCMS.