SQL injection vulnerability in pub/m_pending_news/delete_pending_news.jsp in Enorth Webpublisher CMS allows remote attackers to execute arbitrary SQL commands via the cbNewsId parameter.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/133082/Enorth-Webpublisher-CMS-SQL-Injection.html | Exploit Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2015/Aug/55 | Exploit Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2020-02-12 15:15
Updated : 2024-02-28 17:28
NVD link : CVE-2015-5617
Mitre link : CVE-2015-5617
CVE.ORG link : CVE-2015-5617
JSON object : View
Products Affected
enorth
- webpublisher_cms
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')