New-CMS Multiple Local File Include and HTML-Injection Vulnerabilities
BID:38307
Info
New-CMS Multiple Local File Include and HTML-Injection Vulnerabilities
| Bugtraq ID: | 38307 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2010 12:00AM |
| Updated: | Feb 19 2010 12:21AM |
| Credit: | Alberto Fontanella |
| Vulnerable: |
New-CMS New-CMS 1.08 |
| Not Vulnerable: | |
Discussion
New-CMS Multiple Local File Include and HTML-Injection Vulnerabilities
New-CMS is prone to multiple local file-include vulnerabilities and an HTML-Injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerabilities using directory-traversal strings to view and execute a crafted 'cmd.php' script within the context of the webserver process. Information harvested may aid in further attacks.
The attacker may leverage the HTML-Injection issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
New-CMS 1.08 is vulnerable; other versions may also be affected.
New-CMS is prone to multiple local file-include vulnerabilities and an HTML-Injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit the local file-include vulnerabilities using directory-traversal strings to view and execute a crafted 'cmd.php' script within the context of the webserver process. Information harvested may aid in further attacks.
The attacker may leverage the HTML-Injection issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
New-CMS 1.08 is vulnerable; other versions may also be affected.
Exploit / POC
New-CMS Multiple Local File Include and HTML-Injection Vulnerabilities
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/pdf.php?lng=cmd.php
http://www.example.com/newcms/struttura/manager.php?lng=cmd.php
http://www.example.com/newcms/struttura/editor/quote.php?lng=cmd.php
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/pdf.php?lng=cmd.php
http://www.example.com/newcms/struttura/manager.php?lng=cmd.php
http://www.example.com/newcms/struttura/editor/quote.php?lng=cmd.php
Solution / Fix
New-CMS Multiple Local File Include and HTML-Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
New-CMS Multiple Local File Include and HTML-Injection Vulnerabilities
References:
References:
- New-CMS Homepage (New-CMS)