Description
SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands via the TroncoID parameter.
Exploits (1)
References (3)
Core 3
Core References
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/32660
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/66590
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/105364
Scores
EPSS
0.0038
EPSS Percentile
59.4%
Details
CWE
CWE-89
Status
published
Products (1)
construtiva/cis_manager_cms
Published
Apr 11, 2014
Tracked Since
Feb 18, 2026