Description
|
|
Multiple vulnerabilities have been identified in WavelinkMedia TutorialCMS, which could be exploited by remote attackers to execute arbitrary SQL queries or scripting code. These issues are caused by input validation errors in the "browseCat.php", "browseSubCat.php", "openTutorial.php", "search.php", "topFrame.php" and "admin/editListing.php" scripts when processing the "catFile", "id" and "search" parameters, which could be exploited by malicious people to conduct SQL injection and cross site scripting attacks.
|