CVE-2018-17888
12.10.2018, 14:29
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.Enginsight
Vendor | Product | Version |
---|---|---|
nuuo | nuuo_cms | 𝑥 ≤ 3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration