razorCMS 'admin/index.php' HTML Injection Vulnerability
BID:40373
Info
razorCMS 'admin/index.php' HTML Injection Vulnerability
| Bugtraq ID: | 40373 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2010 12:00AM |
| Updated: | May 24 2010 12:00AM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: |
Morgan Integrated Systems razorCMS 1.0 |
| Not Vulnerable: | |
Discussion
razorCMS 'admin/index.php' HTML Injection Vulnerability
razorCMS is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
razorCMS 1.0 Stable is vulnerable; other versions may also be affected.
razorCMS is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
razorCMS 1.0 Stable is vulnerable; other versions may also be affected.
Exploit / POC
razorCMS 'admin/index.php' HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
An exploit is available.
Attackers can use a browser to exploit this issue.
An exploit is available.
Solution / Fix
razorCMS 'admin/index.php' HTML Injection Vulnerability
Solution:
The vendor has fixed the issue by releasing a patch. Please see the references for more information.
Morgan Integrated Systems razorCMS 1.0
Solution:
The vendor has fixed the issue by releasing a patch. Please see the references for more information.
Morgan Integrated Systems razorCMS 1.0
-
Morgan Integrated Systems upgrade_core1stableSF1.zip
http://www.razorcms.co.uk/archive/blade_packs/upgrade/upgrade_core1sta bleSF1.zip
References
razorCMS 'admin/index.php' HTML Injection Vulnerability
References:
References:
- razorCMS Homepage (Morgan Integrated Systems)
- XSS vulnerability in razorCMS (High-Tech Bridge SA)