1024cms Multiple Input Validation Vulnerabilities
BID:47282
Info
1024cms Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 47282 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2011 12:00AM |
| Updated: | Apr 08 2011 12:00AM |
| Credit: | QSecure and Demetris Papapetrou |
| Vulnerable: |
1024Cms 1024cms 1.1.0 beta |
| Not Vulnerable: | |
Discussion
1024cms Multiple Input Validation Vulnerabilities
1024cms is prone to multiple cross-site scripting vulnerabilities, multiple local file-include vulnerabilities, and a directory-traversal vulnerability
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and open or run arbitrary files in the context of the webserver process ad gain access to sensitive information.
1024cms 1.1.0 beta is vulnerable; other versions may also be affected.
1024cms is prone to multiple cross-site scripting vulnerabilities, multiple local file-include vulnerabilities, and a directory-traversal vulnerability
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and open or run arbitrary files in the context of the webserver process ad gain access to sensitive information.
1024cms 1.1.0 beta is vulnerable; other versions may also be affected.
Exploit / POC
1024cms Multiple Input Validation Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
Solution / Fix
1024cms Multiple Input Validation Vulnerabilities
Solution:
Currently, we are not aware of any patches. If you feel we are in error or if you are aware of more recent
information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any patches. If you feel we are in error or if you are aware of more recent
information, please mail us at: [email protected].
References
1024cms Multiple Input Validation Vulnerabilities
References:
References:
- 1024 CMS Homepage (Treble Designs)
- [[email protected]: XSS Vulnerability in 1024cms Admin Control Panel v1.1.0 ( [email protected])
- [[email protected]: LFI Vulnerability in 1024cms Admin Control Panel v1.1.0 B ( [email protected])
- Directory Traversal Vulnerability in 1024cms Admin Control Panel ([email protected])
- LFI Vulnerability in 024cms Admin Control Panel v1.1.0 Beta ([email protected])
- XSS Vulnerabilities in 1024cms Admin Control Panel v1.1.0 Beta ([email protected])