SQL injection vulnerability in pub/m_pending_news/delete_pending_news.jsp in Enorth Webpublisher CMS allows remote attackers to execute arbitrary SQL commands via the cbNewsId parameter.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/133082/Enorth-Webpublisher-CMS-SQL-Injection.html | Exploit Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2015/Aug/55 | Exploit Mailing List Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-12T14:30:26
Updated: 2020-02-12T14:30:26
Reserved: 2015-07-22T00:00:00
Link: CVE-2015-5617
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-02-12T15:15:11.743
Modified: 2020-02-14T14:41:59.437
Link: CVE-2015-5617
JSON object: View
Redhat Information
No data.
CWE