Multiple vulnerabilities in multiple web applications
ZSL-2012-5097 – SiNG cms 2.9.0 (email) Remote XSS POST Injection Vulnerability
ZSL-2012-5098 – web@all CMS 2.0 Multiple Remote XSS Vulnerabilities
ZSL-2012-5099 – web@all CMS 2.0 (_order) SQL Injection Vulnerability
ZSL-2012-5100 – KindEditor 4.1.2 (name parameter) Reflected XSS Vulnerability
ZSL-2012-5101 – Monstra 1.2.1 Multiple HTML Injection Vulnerabilities
ZSL-2012-5102 – xt:Commerce v4.0.15 (products_name_de) Script Insertion Vulnerability
The applications suffer from multiple stored and reflected XSS vulnerabilities including an SQL Injection.










