← Voltar para CVEs
CVE-2016-7400
N/ADescricao
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action, or (3) content_id parameter in a showComments expComment controller action.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado2/7/2017
Ultima modificacao4/20/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
exponentcms:exponent_cms
Fraquezas (CWE)
CWE-89
Referencias
http://www.openwall.com/lists/oss-security/2016/09/18/10(cve@mitre.org)
http://www.openwall.com/lists/oss-security/2016/09/18/2(cve@mitre.org)
http://www.securityfocus.com/bid/93041(cve@mitre.org)
https://exponentcms.lighthouseapp.com/projects/61783/changesets/e916702a91a6342bbab483a2be2ba2f11dca3aa3(cve@mitre.org)
https://github.com/exponentcms/exponent-cms/commit/e916702a91a6342bbab483a2be2ba2f11dca3aa3(cve@mitre.org)
https://www.exploit-db.com/exploits/40412/(cve@mitre.org)
http://www.openwall.com/lists/oss-security/2016/09/18/10(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2016/09/18/2(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/93041(af854a3a-2127-422b-91ae-364da2661108)
https://exponentcms.lighthouseapp.com/projects/61783/changesets/e916702a91a6342bbab483a2be2ba2f11dca3aa3(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/exponentcms/exponent-cms/commit/e916702a91a6342bbab483a2be2ba2f11dca3aa3(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/exponentcms/exponent-cms/releases/tag/v2.4.0(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/40412/(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.