doorGets CMS Multiple Security Vulnerabilities
BID:65905
Info
doorGets CMS Multiple Security Vulnerabilities
| Bugtraq ID: | 65905 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2014 12:00AM |
| Updated: | Feb 28 2014 12:00AM |
| Credit: | HauntIT |
| Vulnerable: |
doorGets doorGets CMS 6.0 |
| Not Vulnerable: | |
Discussion
doorGets CMS Multiple Security Vulnerabilities
doorGets CMS is prone to the following security vulnerabilities:
1. A cross-site scripting vulnerability.
2. An HTML-injection vulnerability.
3. An information-disclosure vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials or gain access to sensitive information.
doorGets CMS 6.0 is vulnerable; other versions may also be affected.
doorGets CMS is prone to the following security vulnerabilities:
1. A cross-site scripting vulnerability.
2. An HTML-injection vulnerability.
3. An information-disclosure vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials or gain access to sensitive information.
doorGets CMS 6.0 is vulnerable; other versions may also be affected.
Exploit / POC
doorGets CMS Multiple Security Vulnerabilities
Attackers can exploit this issue using a browser or readily available tools. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue using a browser or readily available tools. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
doorGets CMS Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].