Description
Ektron CMS400.NET is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the ContentRatingGraph.aspx script using the res parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.
Remediation
Upgrade to the latest version Ektron CMS.
References
Ektron CMS400.NET ContentRatingGraph.aspx SQL injection
Ektron CMS400.NET 'ContentRatingGraph.aspx' SQL Injection Vulnerability
Related Vulnerabilities
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-7060)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1509)
PHP Improper Input Validation Vulnerability (CVE-2013-7327)
MySQL Improper Input Validation Vulnerability (CVE-2009-4028)