Viscacha Forum CMS v0.8.1.1 – Multiple Web Vulnerabilities
The Vulnerability Laboratory Research Team discovered multiple web vulnerabilities in Viscacha Bulletin Board CMS v0.8.1.1. A remote SQL Injection vulnerability (POST) is detected in Viscacha Bulletin Board CMS v0.8.1.1. The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms. Successful exploitation of the vulnerability results in dbms & application compromise. The vulnerability is located on the bbcode module of the forum application. A remote Cross Site Scripting vulnerability is detected in Viscacha Bulletin Board CMS v0.8.1.1. The vulnerability allows an attacker (remote) or local low privileged user account to inject own malicious script codes on the application-side of the vulnerable module. The vulnerability is located on the bbcode module of the forum application.