vendor:
4Site CMS
by:
D.Mortalov
7.5
CVSS
HIGH
Multiple Remote SQL Injections
89
CWE
Product Name: 4Site CMS
Affected Version From: 2.6 and below
Affected Version To: 2.6
Patch Exists: YES
Related CWE: N/A
CPE: a:4site:4site_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
[WSEC-09-002] 4Site CMS <= 2.6 Multiple Remote SQL Injections
4Site CMS version 2.6 and below is vulnerable to multiple remote SQL injections. An attacker can bypass authentication by using '1'or'1' as the username and password. Additionally, the 'Pages', 'Portfolio', 'Hotels', 'News', and 'FAQ' modules are vulnerable to SQL injection attacks.
Mitigation:
Upgrade to the latest version of 4Site CMS and ensure that all modules are up to date.