BLOG:CMS Multiple Input Validation Vulnerabilities
BID:27317
Info
BLOG:CMS Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 27317 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0359 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Alexandr Polyakov and Stas Svistunovich of Digital Security Research Group are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
BLOG:CMS BLOG:CMS 4.2.1 .b |
| Not Vulnerable: |
BLOG:CMS BLOG:CMS 4.2.1 .c |
Discussion
BLOG:CMS Multiple Input Validation Vulnerabilities
BLOG:CMS is prone to multiple input-validation vulnerabilities, including SQL-injection and cross-site scripting issues, because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
BLOG:CMS 4.2.1.b is vulnerable to these issues; prior versions may also be affected.
BLOG:CMS is prone to multiple input-validation vulnerabilities, including SQL-injection and cross-site scripting issues, because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
BLOG:CMS 4.2.1.b is vulnerable to these issues; prior versions may also be affected.
Exploit / POC
BLOG:CMS Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit cross-site scripting vulnerabilities, the attacker must entice a victim user to follow a malicious URI.
The following example URIs are available:
An attacker can exploit these issues via a browser. To exploit cross-site scripting vulnerabilities, the attacker must entice a victim user to follow a malicious URI.
The following example URIs are available:
Solution / Fix
BLOG:CMS Multiple Input Validation Vulnerabilities
Solution:
The vendor has released updated software to address these issues. Please see the references for more information.
BLOG:CMS BLOG:CMS 4.2.1 .b
Solution:
The vendor has released updated software to address these issues. Please see the references for more information.
BLOG:CMS BLOG:CMS 4.2.1 .b
-
BLOG:CMS blogcms.4.2.1.c.7z
http://downloads.sourceforge.net/blogcms/blogcms.4.2.1.c.7z?modtime=12 00429177&big_mirror=0
References
BLOG:CMS Multiple Input Validation Vulnerabilities
References:
References:
- BLOG:CMS Changelog (BLOG:CMS)
- BLOG:CMS Homepage (BLOG:CMS)
- [DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities ("Digital Security Research Group \[DSecRG\]"
)