Multiple SQL Injection Vulnerabilities in MediaCAST 8 and Earlier

Multiple SQL Injection Vulnerabilities in MediaCAST 8 and Earlier

CVE-2011-2080 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Multiple SQL injection vulnerabilities in MediaCAST 8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) a CP_ENLARGESTYLE cookie to the default URI under inventivex/managetraining/ or (2) unspecified input to authenticate_ad_setup_finished.cfm.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.