AtomCMS SQL Injection and Arbitrary File Upload Vulnerabilities
BID:68437
Info
AtomCMS SQL Injection and Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 68437 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-4852 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2014 12:00AM |
| Updated: | Jul 14 2014 12:07AM |
| Credit: | Jagriti Sahu |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
AtomCMS SQL Injection and Arbitrary File Upload Vulnerabilities
AtomCMS is prone to an SQL-injection vulnerability and an arbitrary file-upload vulnerability.
Exploiting these issues could allow an attacker to upload arbitrary files, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
AtomCMS is prone to an SQL-injection vulnerability and an arbitrary file-upload vulnerability.
Exploiting these issues could allow an attacker to upload arbitrary files, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
AtomCMS SQL Injection and Arbitrary File Upload Vulnerabilities
An attacker can exploit these issues using a web browser.
The following exploit URL is available:
http://www.example.com/acms/admin/uploads.php?id=1
An attacker can exploit these issues using a web browser.
The following exploit URL is available:
http://www.example.com/acms/admin/uploads.php?id=1
Solution / Fix
AtomCMS SQL Injection and Arbitrary File Upload Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
AtomCMS SQL Injection and Arbitrary File Upload Vulnerabilities
References:
References: