vendor:
Wolf CMS
by:
Vulnerability Laboratory Research Team
8,8
CVSS
HIGH
SQL Injection & Persistent Input Validation
89, 79
CWE
Product Name: Wolf CMS
Affected Version From: Wolf CMS v0.7.5
Affected Version To: Wolf CMS v0.7.5
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Wolf CMS v0.7.5 – Multiple Web Vulnerabilities
A SQL Injection vulnerability is detected on the Wolfs Content Management System v0.7.5. The vulnerability allows an remote attacker to execute own sql commands on the affected application dbms. Successful exploitation can result in dbms, web-server or application compromise. Multiple persistent vulnerabilities are detected on the Wolfs Content Management System v0.7.5. The bug allows an remote attacker or local low privileged user account to inject persistent malicious script code on application side. Successful exploitation can result in persistent context manipulation on requests, session hijacking & account steal via application side phishing.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries. Ensure that user input is properly sanitized and validated before being used in the application.