admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
References
Link | Resource |
---|---|
https://github.com/novysodope/empireCMS7.5 | Exploit Third Party Advisory |
http://i.3001.net/uploads/Up_imgs/20181117-ce3d7d20372096011393bfda0d6f9d07.png!small | Exploit Third Party Advisory |
http://i.3001.net/uploads/Up_imgs/20181117-95a316d46f9a46dda7c48e541777d1fc.png!small | Exploit Third Party Advisory |
Configurations
Information
Published : 2019-06-07 10:29
Updated : 2019-06-09 12:28
NVD link : CVE-2018-19461
Mitre link : CVE-2018-19461
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
phome
- empirecms