MonkeyCMS Multiple SQL Injection and Remote Command Execution Vulnerabilities
BID:60734
Info
MonkeyCMS Multiple SQL Injection and Remote Command Execution Vulnerabilities
| Bugtraq ID: | 60734 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2013 12:00AM |
| Updated: | Jun 17 2013 12:00AM |
| Credit: | Yashar shahinzadeh, Mormoroth |
| Vulnerable: |
Poisonous Monkey MonkeyCMS 5.3.10 |
| Not Vulnerable: | |
Discussion
MonkeyCMS Multiple SQL Injection and Remote Command Execution Vulnerabilities
MonkeyCMS is prone to multiple SQL-injection and remote command-execution vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to execute arbitrary code, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
MonkeyCMS 5.3.10 is vulnerable; other versions may also be affected.
MonkeyCMS is prone to multiple SQL-injection and remote command-execution vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to execute arbitrary code, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
MonkeyCMS 5.3.10 is vulnerable; other versions may also be affected.
Exploit / POC
MonkeyCMS Multiple SQL Injection and Remote Command Execution Vulnerabilities
An attacker can exploit these issues using a web browser.
The following example data is available:
An attacker can exploit these issues using a web browser.
The following example data is available:
Solution / Fix
MonkeyCMS Multiple SQL Injection and Remote Command Execution Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MonkeyCMS Multiple SQL Injection and Remote Command Execution Vulnerabilities
References:
References:
- MonkeyCMS HomePage (Poisonous Monkey)