Vulnerabilities
Vulnerable Software
Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to execute arbitrary SQL commands via the (1) sectionID parameter to admin/managersection.php, (2) userID parameter to admin/edituser.php, (3) username parameter to admin/admin.php, or (4) title parameter to admin/managerrelated.php.
CVSS Score
6.5
EPSS Score
0.008
Published
2015-01-02
Cross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend in Absolut Engine 1.73 allows remote authenticated users to inject arbitrary web script or HTML via the title parameter.
CVSS Score
3.5
EPSS Score
0.005
Published
2015-01-02


Contact Us

Shodan ® - All rights reserved