Expinion.net News Manager Lite...

- AV AC AU C I A
发布: 2004-03-20
修订: 2025-04-13

Multiple vulnerabilities have been identified in the application that may allow an attacker to carry out SQL injection, cross-site scripting, and account hijacking attacks. The issues exist in the 'comment_add.asp', 'search.asp', 'category_news_headline.asp', 'more.asp', 'category_news.asp', and 'ews_sort.asp' scripts. Further more a cookie account hijacking issue was also discovered in the application that may allow a remote attacker to gain administrative access to application's administrative interface. News Manager Lite 2.5 is reported to be affected by these issues, however, other versions may be affected as well.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息