packetstormsecurity.com
http://packetstormsecurity.com/files/159690/CMS-Made-Simple-2.1.6-Server-Side-Template-Injection.html CVE-2017-16783
CRITICAL
CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
Record summary
CVE-2017-16783 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template InjectionExploitDB exploitby Gurkirat SinghNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-16783 netsparker.com
https://www.netsparker.com/web-applications-advisories/ns-17-032-server-side-template-injection-vulnerability-in-cms-made-simple