H2O-CMS PHP Code Injection and Cookie Authentication Bypass Vulnerabilities
BID:31961
Info
H2O-CMS PHP Code Injection and Cookie Authentication Bypass Vulnerabilities
| Bugtraq ID: | 31961 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2008 12:00AM |
| Updated: | Oct 29 2008 01:16PM |
| Credit: | StAkeR |
| Vulnerable: |
H2O-CMS H2O-CMS 3.4 |
| Not Vulnerable: | |
Discussion
H2O-CMS PHP Code Injection and Cookie Authentication Bypass Vulnerabilities
H2O-CMS is prone to a PHP code-injection vulnerability and a cookie authentication-bypass vulnerability.
An attacker can exploit the PHP code-injection issue to inject and execute arbitrary malicious PHP code in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Attackers can exploit the cookie authentication-bypass vulnerability to gain administrative access; this may aid in further attacks.
Versions up to and including H2O-CMS 3.4 are vulnerable.
H2O-CMS is prone to a PHP code-injection vulnerability and a cookie authentication-bypass vulnerability.
An attacker can exploit the PHP code-injection issue to inject and execute arbitrary malicious PHP code in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Attackers can exploit the cookie authentication-bypass vulnerability to gain administrative access; this may aid in further attacks.
Versions up to and including H2O-CMS 3.4 are vulnerable.
Exploit / POC
H2O-CMS PHP Code Injection and Cookie Authentication Bypass Vulnerabilities
Attackers can exploit these issues via a browser.
The following example JavaScript code is available:
javascript:document.cookie = "admin=1; path=/";
The following exploit code is also available:
Attackers can exploit these issues via a browser.
The following example JavaScript code is available:
javascript:document.cookie = "admin=1; path=/";
The following exploit code is also available:
Solution / Fix
H2O-CMS PHP Code Injection and Cookie Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
H2O-CMS PHP Code Injection and Cookie Authentication Bypass Vulnerabilities
References:
References:
- H2O-CMS Homepage (H2O-CMS)