MCImageManager Multiple Security Vulnerabilities
BID:61825
Info
MCImageManager Multiple Security Vulnerabilities
| Bugtraq ID: | 61825 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2013 12:00AM |
| Updated: | Aug 16 2013 12:00AM |
| Credit: | MustLive |
| Vulnerable: |
Moxiecode Systems MCImageManager 3.1.5 |
| Not Vulnerable: | |
Discussion
MCImageManager Multiple Security Vulnerabilities
MCImageManager is prone to multiple security vulnerabilities.
An attacker may exploit these issues to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, manipulate the page and spoof content to misguide users and to disclose or modify sensitive information. Other attacks may also be possible.
MCImageManager 3.1.5 and prior versions are vulnerable.
MCImageManager is prone to multiple security vulnerabilities.
An attacker may exploit these issues to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, manipulate the page and spoof content to misguide users and to disclose or modify sensitive information. Other attacks may also be possible.
MCImageManager 3.1.5 and prior versions are vulnerable.
Solution / Fix
MCImageManager Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MCImageManager Multiple Security Vulnerabilities
References:
References:
- CS, XSS and FPD vulnerabilities in MCImageManager for TinyMCE (MustLive)
- MCImageManager Homepage (Moxiecode Systems AB)