bloofox CMS Multiple Security Vulnerabilities
BID:65936
Info
bloofox CMS Multiple Security Vulnerabilities
| Bugtraq ID: | 65936 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2014 12:00AM |
| Updated: | Mar 03 2014 12:00AM |
| Credit: | HauntIT |
| Vulnerable: |
Bloofox.com BloofoxCMS 0.5 |
| Not Vulnerable: | |
Discussion
bloofox CMS Multiple Security Vulnerabilities
bloofox CMS is prone to the following security vulnerabilities:
1. A cross-site scripting vulnerability
2. Multiple SQL-injection vulnerabilities
3. A local file-include vulnerability
4. A cross-site request forgery vulnerability
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials, read arbitrary files, access or modify data, exploit latent vulnerabilities in the underlying database or perform certain unauthorized actions and gain access to the affected application.
bloofox CMS 0.5.0 is vulnerable; other versions may also be affected.
bloofox CMS is prone to the following security vulnerabilities:
1. A cross-site scripting vulnerability
2. Multiple SQL-injection vulnerabilities
3. A local file-include vulnerability
4. A cross-site request forgery vulnerability
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials, read arbitrary files, access or modify data, exploit latent vulnerabilities in the underlying database or perform certain unauthorized actions and gain access to the affected application.
bloofox CMS 0.5.0 is vulnerable; other versions may also be affected.
References
bloofox CMS Multiple Security Vulnerabilities
References:
References:
- Bloofox CMS (bloofox.com)
- BlooFox CMS 0.5.0 - Multiple vulnerabilities (HauntIT)