NQcontent CMS "admin/index.cfm" Cross-Site Scripting and Information Disclosure Vulnerabilities

30 July 2010
Bookmark and Share
NQcontent CMS is a content management application. The application is exposed to multiple issues. An information disclosure issue exists because it fails to restrict access to sensitive information. A cross-site scripting issue exists because the application fails to sufficiently sanitize user-supplied input to the "login" POST parameter of the "admin/index.cfm" script.

Ref: http://www.securityfocus.com/bid/41799

10.30.30 - CVE: Not Available
Platform: Web Application - Cross Site Scripting