TomatoCMS Multiple Security Vulnerabilities
BID:40544
Info
TomatoCMS Multiple Security Vulnerabilities
| Bugtraq ID: | 40544 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1514 CVE-2010-1515 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2010 12:00AM |
| Updated: | Jun 03 2010 12:00AM |
| Credit: | Russ McRee, HolisticInfoSec, Secunia Research |
| Vulnerable: |
TIG TomatoCMS 2.0.6 |
| Not Vulnerable: | |
Discussion
TomatoCMS Multiple Security Vulnerabilities
TomatoCMS is prone to multiple security vulnerabilities. These vulnerabilities include multiple cross-site scripting vulnerabilites, multiple HTML-injection vulnerabilities, a cross-site request-forgery vulnerability, and an arbitrary file-upload vulnerability.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions, disclose or modify sensitive information, or upload arbitrary code and run it in the context of the webserver process. Other attacks are also possible.
TomatoCMS 2.0.6 is vulnerable; other versions may also be affected.
TomatoCMS is prone to multiple security vulnerabilities. These vulnerabilities include multiple cross-site scripting vulnerabilites, multiple HTML-injection vulnerabilities, a cross-site request-forgery vulnerability, and an arbitrary file-upload vulnerability.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions, disclose or modify sensitive information, or upload arbitrary code and run it in the context of the webserver process. Other attacks are also possible.
TomatoCMS 2.0.6 is vulnerable; other versions may also be affected.
Exploit / POC
TomatoCMS Multiple Security Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
TomatoCMS Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
TomatoCMS Multiple Security Vulnerabilities
References:
References: