The provided text describes SQL injection and XSS vulnerabilities in CMS Touch 2.01, with a proof-of-concept URL demonstrating the SQLi vector. It lacks functional exploit code but includes technical details about the vulnerability and its impact.
Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Reliable
Target:CMS Touch 2.01
No auth needed
Prerequisites:Access to the vulnerable news.php endpoint