MyCMS Multiple Input Validation Vulnerabilities
BID:24757
Info
MyCMS Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 24757 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3586 CVE-2007-3587 CVE-2007-3585 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | BlackHawk is credited with discovering these vulnerabilities. |
| Vulnerable: |
MyCMS MyCMS 0.9.8 |
| Not Vulnerable: | |
Discussion
MyCMS Multiple Input Validation Vulnerabilities
MyCMS is prone to multiple input-validation vulnerabilities, including remote file-include issues, authentication-bypass issues, and arbitrary-command-execution issues.
Successful exploits will allow remote attackers to execute arbitrary system commands and PHP script code in the context of the affected webserver, to bypass authentication, and to compromise the vulnerable application.
These issues affect MyCMS 0.9.8 and prior versions.
MyCMS is prone to multiple input-validation vulnerabilities, including remote file-include issues, authentication-bypass issues, and arbitrary-command-execution issues.
Successful exploits will allow remote attackers to execute arbitrary system commands and PHP script code in the context of the affected webserver, to bypass authentication, and to compromise the vulnerable application.
These issues affect MyCMS 0.9.8 and prior versions.
Exploit / POC
MyCMS Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit these issues.
The following exploits are available:
Attackers can use a browser to exploit these issues.
The following exploits are available:
Solution / Fix
MyCMS Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].