Source: Zero Science Lab Blog

Zero Science Lab Blog Ametys CMS 3.5.2 (lang parameter) XPath Injection Vulnerability

Input passed via the 'lang' POST parameter in the newsletter plugin is not properly sanitised before being used to construct a XPath query for XML data. This can be exploited to manipulate XPath queries by injecting arbitrary XPath code. Advisory: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5162.php

Read full article »
Est. Annual Revenue
$100K-5.0M
Est. Employees
1-25
CEO Avatar

CEO

Update CEO

CEO Approval Rating

- -/100