CMS Mini 'guestbook' Remote Command Execution Vulnerability

CMS Mini is prone to a vulnerability that attackers can leverage to execute arbitrary commands in the context of the application. This issue occurs because the application fails to adequately sanitize user-supplied input.

Successful attacks can compromise the affected application and possibly the underlying computer.

CMS Mini 0.2.2 is vulnerable; other versions may also be affected.


 

Privacy Statement
Copyright 2010, SecurityFocus