Ektron CMS 'xmlrpc.aspx' XML Injection Vulnerability
BID:55404
Info
Ektron CMS 'xmlrpc.aspx' XML Injection Vulnerability
| Bugtraq ID: | 55404 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2012 12:00AM |
| Updated: | Sep 05 2012 12:00AM |
| Credit: | Phil Taylor and Nadeem Salim from Sense of Security Labs. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Ektron CMS 'xmlrpc.aspx' XML Injection Vulnerability
Ektron CMS is prone to an XML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attackers can exploit this issue to scan the perimeter behind the firewall or include files from the local file system.
Ektron CMS 8.5.0 is vulnerable; other versions may also be affected.
Ektron CMS is prone to an XML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attackers can exploit this issue to scan the perimeter behind the firewall or include files from the local file system.
Ektron CMS 8.5.0 is vulnerable; other versions may also be affected.
Exploit / POC
Ektron CMS 'xmlrpc.aspx' XML Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example input data is available:
Attackers can use a browser to exploit this issue.
The following example input data is available:
Solution / Fix
Ektron CMS 'xmlrpc.aspx' XML Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Ektron CMS 'xmlrpc.aspx' XML Injection Vulnerability
References:
References: