vendor:
OneCMS
by:
5.5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: OneCMS
Affected Version From: 2.6.2004
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
SQL Injection Vulnerabilities in OneCMS
Multiple SQL-injection vulnerabilities in OneCMS allow attackers to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Mitigation:
Sanitize user-supplied data before using it in an SQL query.