Home / exploitsPDF  

SetSeed CMS 5.8.20 SQL Injection

Posted on 03 November 2011

SetSeed CMS version 5.8.20 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the vulnerable script using the cookie input 'loggedInUser', which could allow the attacker to view, add, modify or delete information in the back-end database.

 

TOP