VigileCMS Multiple Remote Vulnerabilities
BID:26543
Info
VigileCMS Multiple Remote Vulnerabilities
| Bugtraq ID: | 26543 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 22 2007 12:00AM |
| Updated: | Nov 22 2007 10:04PM |
| Credit: | Paradox is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
IT cms Vigile CMS 1.8 |
| Not Vulnerable: | |
Discussion
VigileCMS Multiple Remote Vulnerabilities
VigileCMS is prone to a remote privilege escalation vulnerability, arbitrary file-overwrite vulnerability, and other unspecified vulnerabilities.
An attacker can exploit these issues to gain administrative access to the affected application and overwrite arbitrary files within the context of the webserver. Attackers who have administrative access and can overwrite arbitrary files will be able to execute arbitrary commands within the context of the webserver. Other attacks are also possible.
These issues affect VigileCMS 1.8; other versions may also be affected.
VigileCMS is prone to a remote privilege escalation vulnerability, arbitrary file-overwrite vulnerability, and other unspecified vulnerabilities.
An attacker can exploit these issues to gain administrative access to the affected application and overwrite arbitrary files within the context of the webserver. Attackers who have administrative access and can overwrite arbitrary files will be able to execute arbitrary commands within the context of the webserver. Other attacks are also possible.
These issues affect VigileCMS 1.8; other versions may also be affected.
Exploit / POC
VigileCMS Multiple Remote Vulnerabilities
An attacker can use a browser to exploit these issues.
The following exploit code is available:
An attacker can use a browser to exploit these issues.
The following exploit code is available:
Solution / Fix
VigileCMS Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
VigileCMS Multiple Remote Vulnerabilities
References:
References: