moziloCMS Prior to 1.10.3 Multiple Vulnerabilities
BID:31495
Info
moziloCMS Prior to 1.10.3 Multiple Vulnerabilities
| Bugtraq ID: | 31495 |
| Class: | Unknown |
| CVE: |
CVE-2008-6128 CVE-2008-6126 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | David Vieira-Kurz |
| Vulnerable: |
moziloCMS moziloCMS 1.10.1 mozilo moziloCMS 1.10.2 |
| Not Vulnerable: |
moziloCMS moziloCMS 1.11.2 mozilo moziloCMS 1.10.3 |
Discussion
moziloCMS Prior to 1.10.3 Multiple Vulnerabilities
moziloCMS is prone to multiple vulnerabilities, including a session-fixation issue, multiple directory-traversal issues, and multiple cross-site scripting issues.
An attacker may leverage these issues to view arbitrary local files within the context of the webserver, to execute arbitrary script code in the browser of an unsuspecting user, or to hijack a valid user's session.
Versions prior to moziloCMS 1.10.3 are vulnerable.
UPDATE (September 22, 2009): Further reports indicate that some or all of these issues may have been re-introduced in versions prior to moziloCMS 1.11.2.
moziloCMS is prone to multiple vulnerabilities, including a session-fixation issue, multiple directory-traversal issues, and multiple cross-site scripting issues.
An attacker may leverage these issues to view arbitrary local files within the context of the webserver, to execute arbitrary script code in the browser of an unsuspecting user, or to hijack a valid user's session.
Versions prior to moziloCMS 1.10.3 are vulnerable.
UPDATE (September 22, 2009): Further reports indicate that some or all of these issues may have been re-introduced in versions prior to moziloCMS 1.11.2.
Exploit / POC
moziloCMS Prior to 1.10.3 Multiple Vulnerabilities
Attackers can exploit these issues through a browser. To exploit the cross-site scripting and session-fixation issues, the attacker must entice unsuspecting users to follow a malicious URI.
Attackers can exploit these issues through a browser. To exploit the cross-site scripting and session-fixation issues, the attacker must entice unsuspecting users to follow a malicious URI.
Solution / Fix
moziloCMS Prior to 1.10.3 Multiple Vulnerabilities
Solution:
The vendor has released updates. Please see the references for details.
moziloCMS moziloCMS 1.10.1
moziloCMS moziloCMS 1.10.2
Solution:
The vendor has released updates. Please see the references for details.
moziloCMS moziloCMS 1.10.1
-
mozilo mozilocms1_10_3.zip
http://cms.mozilo.de/download.php?cat=10_moziloCMS&file=mozilocms1_10_ 3.zip
moziloCMS moziloCMS 1.10.2
-
mozilo mozilocms1_10_3.zip
http://cms.mozilo.de/download.php?cat=10_moziloCMS&file=mozilocms1_10_ 3.zip
References
moziloCMS Prior to 1.10.3 Multiple Vulnerabilities
References:
References: