Contenido CMS Unspecified Remote Command Execution Vulnerability
BID:15790
Info
Contenido CMS Unspecified Remote Command Execution Vulnerability
| Bugtraq ID: | 15790 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-4132 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2005 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | This vulnerability was reported by the vendor. |
| Vulnerable: |
Contenido Contenido 4.6.1 Contenido Contenido 4.6 |
| Not Vulnerable: |
Contenido Contenido 4.6.4 |
Discussion
Contenido CMS Unspecified Remote Command Execution Vulnerability
Contenido CMS is prone to an unspecified remote command execution vulnerability. This is due to a lack of proper sanitization of user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary commands in the context of the Web server process. This may facilitate a compromise of the underlying system; other attacks are also possible.
It should be notes that the "allow_url_fopen" and "register_globals" PHP variables must be enabled to exploit this vulnerability.
Contenido CMS is prone to an unspecified remote command execution vulnerability. This is due to a lack of proper sanitization of user-supplied input.
An attacker can exploit this vulnerability to execute arbitrary commands in the context of the Web server process. This may facilitate a compromise of the underlying system; other attacks are also possible.
It should be notes that the "allow_url_fopen" and "register_globals" PHP variables must be enabled to exploit this vulnerability.
Exploit / POC
Contenido CMS Unspecified Remote Command Execution Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Contenido CMS Unspecified Remote Command Execution Vulnerability
Solution:
The vendor has released version 4.6.4 to address this issue.
Contenido Contenido 4.6
Contenido Contenido 4.6.1
Solution:
The vendor has released version 4.6.4 to address this issue.
Contenido Contenido 4.6
-
Contenido contenido-4.6.4.zip
http://www.contenido.org/opensourcecms/de/upload/versionen/contenido-4 .6.4.zip
Contenido Contenido 4.6.1
-
Contenido contenido-4.6.4.zip
http://www.contenido.org/opensourcecms/de/upload/versionen/contenido-4 .6.4.zip
References
Contenido CMS Unspecified Remote Command Execution Vulnerability
References:
References:
- Contenido 4.6.4 Changelog (Contenido)
- Downloads for the CMS (Contenido)