CVE-2020-23966 Information

Description

SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.

Reference

https://github.com/VictorAlagwu/CMSsite/issues/15 https://github.com/VictorAlagwu/CMSsite/

Share on: