Jasmine CMS Multiple Input Validation Vulnerabilities
BID:24546
Info
Jasmine CMS Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 24546 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3312 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Silentz is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Efstratios Geroulis Jasmine CMS 1.0 |
| Not Vulnerable: |
Efstratios Geroulis Jasmine CMS 1.1 |
Discussion
Jasmine CMS Multiple Input Validation Vulnerabilities
Jasmine CMS is prone to multiple input-validation vulnerabilities, including multiple SQL-injection issues and a local file-include issue.
Exploiting these issues may allow an unauthorized user to view and execute local scripts, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects Jasmine CMS 1.0; other versions may also be affected.
Jasmine CMS is prone to multiple input-validation vulnerabilities, including multiple SQL-injection issues and a local file-include issue.
Exploiting these issues may allow an unauthorized user to view and execute local scripts, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects Jasmine CMS 1.0; other versions may also be affected.
Exploit / POC
Jasmine CMS Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit these issues.
The following exploit code is available:
Attackers can use a browser to exploit these issues.
The following exploit code is available:
Solution / Fix
Jasmine CMS Multiple Input Validation Vulnerabilities
Solution:
The vendor has released Jasmine CMS 1.1 to address these issues.
Solution:
The vendor has released Jasmine CMS 1.1 to address these issues.
References
Jasmine CMS Multiple Input Validation Vulnerabilities
References:
References:
- Jasmine Portal Homepage (Efstratios Geroulis)