Description
Ektron CMS400.NET is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the ContentRatingGraph.aspx script using the res parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.
Remediation
Upgrade to the latest version Ektron CMS.
References
Ektron CMS400.NET ContentRatingGraph.aspx SQL injection
Ektron CMS400.NET 'ContentRatingGraph.aspx' SQL Injection Vulnerability
Related Vulnerabilities
WordPress Plugin LearnPress-WordPress LMS SQL Injection (4.1.3.2)
WordPress Plugin WordPress Clean Up & Optimizer-Clean Up Optimizer SQL Injection (3.0.13)
WordPress Plugin Spam protection, AntiSpam, FireWall by CleanTalk SQL Injection (5.185)
WordPress Plugin User Self Delete SQL Injection (1.1)
WordPress Plugin Ultimate Maps by Supsystic SQL Injection (1.1.12)