CVE-2011-2080

MediaCAST < 8 - SQL Injection via CP_ENLARGESTYLE Cookie or authenticate_ad_setup_finished.cfm

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in MediaCAST 8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) a CP_ENLARGESTYLE cookie to the default URI under inventivex/managetraining/ or (2) unspecified input to authenticate_ad_setup_finished.cfm.

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44182
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67220
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8245
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67221

Scores

EPSS 0.0185
EPSS Percentile 76.9%

Details

CWE
CWE-89
Status published
Products (1)
inventivetec/mediacast < 8
Published May 10, 2011
Tracked Since Feb 18, 2026