vendor:
VigileCMS
by:
DevilAuron
N/A
CVSS
N/A
Permanent Xss, Local File Inclusion, CSRF
Unknown
CWE
Product Name: VigileCMS
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE:
CPE: Unknown
Platforms Tested: Unknown
2007
VigileCMS Multiple Vulnerabilities
The Permanent Xss vulnerability allows an attacker to insert XSS code in the message of the vedipm module and live_chat module. The Local File Inclusion vulnerability allows an attacker to include any file present on the server by manipulating the 'module' parameter in the index.php file. The CSRF vulnerability is also present.
Mitigation:
Unknown