Squiz CMS Remote File Disclosure Vulnerability
BID:55148
Info
Squiz CMS Remote File Disclosure Vulnerability
| Bugtraq ID: | 55148 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2012 12:00AM |
| Updated: | Aug 22 2012 12:00AM |
| Credit: | Robert Ray of NGSSecure |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Squiz CMS Remote File Disclosure Vulnerability
Squiz CMS is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in further attacks.
Squiz CMS is prone to a remote file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in further attacks.
Exploit / POC
Squiz CMS Remote File Disclosure Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
Squiz CMS Remote File Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Squiz CMS Remote File Disclosure Vulnerability
References:
References: