e107 CMS Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
BID:42600
Info
e107 CMS Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 42600 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2010 12:00AM |
| Updated: | Aug 22 2010 12:00AM |
| Credit: | Justin Klein Keane |
| Vulnerable: |
e107 e107 0.7.22 |
| Not Vulnerable: |
e107 e107 0.7.23 |
Discussion
e107 CMS Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
e107 CMS is prone to a cross-site request-forgery vulnerability and a cross-site scripting vulnerability.
An attacker can exploit the cross-site request forgery issue to perform unauthorized actions in the context of other user's session. This may aid in other attacks.
The attacker can exploit the cross-site scripting issues to execute arbitrary script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials. Other attacks are also possible.
e107 CMS version 0.7.22 is vulnerable; others may also be affected.
e107 CMS is prone to a cross-site request-forgery vulnerability and a cross-site scripting vulnerability.
An attacker can exploit the cross-site request forgery issue to perform unauthorized actions in the context of other user's session. This may aid in other attacks.
The attacker can exploit the cross-site scripting issues to execute arbitrary script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials. Other attacks are also possible.
e107 CMS version 0.7.22 is vulnerable; others may also be affected.
Exploit / POC
e107 CMS Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
An attacker can exploit these issues with readily available tools.
An attacker can exploit these issues with readily available tools.
Solution / Fix
e107 CMS Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
e107 CMS Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
References:
References:
- Home page (e107)