GetSimple CMS Multiple Vulnerabilities
BID:59601
Info
GetSimple CMS Multiple Vulnerabilities
| Bugtraq ID: | 59601 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2013 12:00AM |
| Updated: | Mar 19 2015 08:37AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Cagintranet Networks GetSimple CMS 3.1 Cagintranet Networks GetSimple CMS 2.01 |
| Not Vulnerable: | |
Discussion
GetSimple CMS Multiple Vulnerabilities
GetSimple CMS is prone to the following vulnerabilities:
1. A cross-site scripting vulnerability
2. An HTML-injection vulnerability
3. Multiple directory-traversal vulnerabilities
4. An arbitrary-code execution vulnerability
Attackers can exploit these issues to steal cookie-based authentication credentials, to execute arbitrary local scripts in the context of the web server process, to obtain potentially sensitive information, or to execute arbitrary code in the context of the affected application.
Versions prior to GetSimple CMS 3.2.1 are vulnerable.
GetSimple CMS is prone to the following vulnerabilities:
1. A cross-site scripting vulnerability
2. An HTML-injection vulnerability
3. Multiple directory-traversal vulnerabilities
4. An arbitrary-code execution vulnerability
Attackers can exploit these issues to steal cookie-based authentication credentials, to execute arbitrary local scripts in the context of the web server process, to obtain potentially sensitive information, or to execute arbitrary code in the context of the affected application.
Versions prior to GetSimple CMS 3.2.1 are vulnerable.
Exploit / POC
GetSimple CMS Multiple Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
GetSimple CMS Multiple Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.