admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
References
Configurations
History
21 Nov 2024, 03:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://i.3001.net/uploads/Up_imgs/20181117-95a316d46f9a46dda7c48e541777d1fc.png%21small - | |
References | () http://i.3001.net/uploads/Up_imgs/20181117-ce3d7d20372096011393bfda0d6f9d07.png%21small - | |
References | () https://github.com/novysodope/empireCMS7.5 - Exploit, Third Party Advisory |
07 Nov 2023, 02:55
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2019-06-07 17:29
Updated : 2024-11-21 03:57
NVD link : CVE-2018-19461
Mitre link : CVE-2018-19461
CVE.ORG link : CVE-2018-19461
JSON object : View
Products Affected
phome
- empirecms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')