Mura CMS Multiple Vulnerabilities
BID:42180
Info
Mura CMS Multiple Vulnerabilities
| Bugtraq ID: | 42180 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2009 12:00AM |
| Updated: | Sep 22 2009 12:00AM |
| Credit: | Vladimir Vorontsov |
| Vulnerable: |
Blue River Interactive Group Mura CMS 5.1 |
| Not Vulnerable: | |
Discussion
Mura CMS Multiple Vulnerabilities
Mura CMS is prone to multiple cross-site scripting vulnerabilities, information disclosure vulnerability and an HTML injection vulnerability because the application fails to sufficiently sanitize user-supplied input.
Attackers can exploit these issues to obtain sensitive information, steal cookie-based authentication information, and execute arbitrary client-side scripts in the context of the browser.
Mura CMS version 5.1 and prior are vulnerable.
Mura CMS is prone to multiple cross-site scripting vulnerabilities, information disclosure vulnerability and an HTML injection vulnerability because the application fails to sufficiently sanitize user-supplied input.
Attackers can exploit these issues to obtain sensitive information, steal cookie-based authentication information, and execute arbitrary client-side scripts in the context of the browser.
Mura CMS version 5.1 and prior are vulnerable.
Exploit / POC
Mura CMS Multiple Vulnerabilities
Attackers can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Mura CMS Multiple Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Mura CMS Multiple Vulnerabilities
References:
References:
- Mura Home Page (Blue River Interactive Group)
- Mura CMS XSS Vulnerability Fix (Blue River Interactive Group)