WebCMS Portal Edition Multiple Input Validation Vulnerabilities
BID:31153
Info
WebCMS Portal Edition Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 31153 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4184 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2008 12:00AM |
| Updated: | Apr 16 2015 05:54PM |
| Credit: | Credited to an anonymous source. |
| Vulnerable: |
WebCMS WebCMS Portal Edition 0 |
| Not Vulnerable: | |
Discussion
WebCMS Portal Edition Multiple Input Validation Vulnerabilities
WebCMS Portal Edition is prone to multiple input-validation vulnerabilities, including:
- An SQL-injection vulnerability
- A cross-site scripting vulnerability
An attacker can exploit these issues to steal cookie-based authentication credentials, control how the site is rendered to the user, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
WebCMS Portal Edition is prone to multiple input-validation vulnerabilities, including:
- An SQL-injection vulnerability
- A cross-site scripting vulnerability
An attacker can exploit these issues to steal cookie-based authentication credentials, control how the site is rendered to the user, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
WebCMS Portal Edition Multiple Input Validation Vulnerabilities
Attackers can exploit these issues through a browser. To exploit the cross-site scripting vulnerabilities, an attacker must entice an unsuspecting victim to follow a malicious URI.
Attackers can exploit these issues through a browser. To exploit the cross-site scripting vulnerabilities, an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
WebCMS Portal Edition Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WebCMS Portal Edition Multiple Input Validation Vulnerabilities
References:
References:
- WebCMS Homepage (WebCMS)