Description
Ektron CMS400.NET is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the ContentRatingGraph.aspx script using the res parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.
Remediation
Upgrade to the latest version Ektron CMS.
References
Ektron CMS400.NET ContentRatingGraph.aspx SQL injection
Ektron CMS400.NET 'ContentRatingGraph.aspx' SQL Injection Vulnerability
Related Vulnerabilities
Vulnerable package dependencies [high]
WordPress Plugin Good LMS-Learning Management System SQL Injection (2.1.4)
WordPress Plugin GD Star Rating 'votes' Parameter SQL Injection (1.9.8)
WordPress Plugin All Video Gallery 'vid' Parameter Multiple SQL Injection Vulnerabilities (1.1)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors SQL Injection (2.0.2)