Goople CMS 'editpass.php' Multiple Remote PHP Code Injection Vulnerabilities
BID:33848
Info
Goople CMS 'editpass.php' Multiple Remote PHP Code Injection Vulnerabilities
| Bugtraq ID: | 33848 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6119 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2008 12:00AM |
| Updated: | Feb 20 2009 08:07PM |
| Credit: | anonymous |
| Vulnerable: |
Goople CMS Goople CMS 1.7 |
| Not Vulnerable: | |
Discussion
Goople CMS 'editpass.php' Multiple Remote PHP Code Injection Vulnerabilities
Goople CMS is prone to multiple vulnerabilities that attackers can leverage to execute arbitrary PHP code because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
Goople CMS 1.7 is vulnerable; other versions may also be affected.
Goople CMS is prone to multiple vulnerabilities that attackers can leverage to execute arbitrary PHP code because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
Goople CMS 1.7 is vulnerable; other versions may also be affected.
Exploit / POC
Goople CMS 'editpass.php' Multiple Remote PHP Code Injection Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Goople CMS 'editpass.php' Multiple Remote PHP Code Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Goople CMS 'editpass.php' Multiple Remote PHP Code Injection Vulnerabilities
References:
References:
- Goople CMS Project Page (Goople CMS)