cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.
References
Link Resource
http://packetstormsecurity.com/files/160129/xuucms-3-SQL-Injection.html Exploit Third Party Advisory VDB Entry
https://github.com/cbkhwx/cxuucmsv3/issues/1 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-11-18T16:45:02

Updated: 2020-11-19T17:06:14

Reserved: 2020-11-02T00:00:00


Link: CVE-2020-28091

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-11-18T17:15:11.867

Modified: 2020-12-01T21:42:24.650


Link: CVE-2020-28091

JSON object: View

cve-icon Redhat Information

No data.

CWE