Contao CMS Multiple PHP Object Injection Vulnerabilities
BID:65293
CVE-2014-1860 |Info
Contao CMS Multiple PHP Object Injection Vulnerabilities
| Bugtraq ID: | 65293 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1860 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 03 2014 12:00AM |
| Updated: | Feb 11 2014 01:36AM |
| Credit: | Pedro Ribeiro of Agile Information Security. |
| Vulnerable: |
Leo Feyer Contao 2.10.1 |
| Not Vulnerable: | |
Discussion
Contao CMS Multiple PHP Object Injection Vulnerabilities
Contao is prone to multiple PHP object-injection vulnerabilities.
Attackers can exploit these issues to inject arbitrary object in to the application. This may allow an attacker to delete files or execute arbitrary PHP code through specially crafted objects.
Versions prior to Contao 2.11.14 and 3.2.5 are vulnerable.
Contao is prone to multiple PHP object-injection vulnerabilities.
Attackers can exploit these issues to inject arbitrary object in to the application. This may allow an attacker to delete files or execute arbitrary PHP code through specially crafted objects.
Versions prior to Contao 2.11.14 and 3.2.5 are vulnerable.
Exploit / POC
Contao CMS Multiple PHP Object Injection Vulnerabilities
An attacker can exploit these issues using a web browser.
An attacker can exploit these issues using a web browser.
Solution / Fix
Contao CMS Multiple PHP Object Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.