Sefrengo CMS CVE-2015-1428 Multiple SQL Injection Vulnerabilities
BID:72452
Info
Sefrengo CMS CVE-2015-1428 Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 72452 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-1428 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 02 2015 12:00AM |
| Updated: | Feb 02 2015 12:00AM |
| Credit: | Nguyen Hung Tuan |
| Vulnerable: |
Sefrengo Sefrengo CMS 1.6.1 |
| Not Vulnerable: |
Sefrengo Sefrengo CMS 1.6.2 |
Discussion
Sefrengo CMS CVE-2015-1428 Multiple SQL Injection Vulnerabilities
Sefrengo CMS is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
An attacker can exploit these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Sefrengo CMS 1.6.1 is vulnerable; other versions may also be affected.
Sefrengo CMS is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
An attacker can exploit these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Sefrengo CMS 1.6.1 is vulnerable; other versions may also be affected.
Exploit / POC
Sefrengo CMS CVE-2015-1428 Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Sefrengo CMS CVE-2015-1428 Multiple SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Sefrengo CMS CVE-2015-1428 Multiple SQL Injection Vulnerabilities
References:
References:
- Sefrengo CMS Home Page (sefrengo)
- Sefrengo v1.6.2 (sefrengo)
- Sefrengo CMS v1.6.1 - Multiple SQL Injection Vulnerabilities (SecLists.Org)