CMSimple Multiple Input Validation Vulnerabilities
BID:29450
Info
CMSimple Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 29450 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2650 |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | irk4z |
| Vulnerable: |
CMSimple Content Management System 3.1 |
| Not Vulnerable: | |
Discussion
CMSimple Multiple Input Validation Vulnerabilities
CMSimple is prone to two input-validation vulnerabilities, including a local file-include vulnerability and an arbitrary-file-upload vulnerability.
An attacker can exploit these issues to retrieve webserver-readable files from the computer or to upload arbitrary files to the computer. The attacker may be able to execute files that have been uploaded, for example, if the attacker uploads a malicious PHP script.
CMSimple is prone to two input-validation vulnerabilities, including a local file-include vulnerability and an arbitrary-file-upload vulnerability.
An attacker can exploit these issues to retrieve webserver-readable files from the computer or to upload arbitrary files to the computer. The attacker may be able to execute files that have been uploaded, for example, if the attacker uploads a malicious PHP script.
Exploit / POC
CMSimple Multiple Input Validation Vulnerabilities
Attackers can exploit these issues via a browser.
The following exploit is available:
Attackers can exploit these issues via a browser.
The following exploit is available:
Solution / Fix
CMSimple Multiple Input Validation Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
CMSimple Multiple Input Validation Vulnerabilities
References:
References:
- CMSimple Home Page (CMSimple)
- Security Fix (CMSimple)
- CMSimple 3.1 Local File Inclusion / Arbitrary File Upload Exploit (milw0rm)