Concrete5 Cross Site Scripting and Path Disclosure Vulnerabilities
BID:68685
Info
Concrete5 Cross Site Scripting and Path Disclosure Vulnerabilities
| Bugtraq ID: | 68685 |
| Class: | Design Error |
| CVE: |
CVE-2014-5107 CVE-2014-5108 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2014 12:00AM |
| Updated: | Aug 01 2014 12:10AM |
| Credit: | Osanda Malith |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Concrete5 Cross Site Scripting and Path Disclosure Vulnerabilities
Concrete5 is prone to a cross-site scripting vulnerability and multiple path-disclosure vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks. The full path-disclosure vulnerability can allow the attacker to obtain sensitive information that can aid in launching further attacks.
Concrete5 5.6.2.1 is vulnerable; other versions may also be affected.
Concrete5 is prone to a cross-site scripting vulnerability and multiple path-disclosure vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks. The full path-disclosure vulnerability can allow the attacker to obtain sensitive information that can aid in launching further attacks.
Concrete5 5.6.2.1 is vulnerable; other versions may also be affected.
Exploit / POC
Concrete5 Cross Site Scripting and Path Disclosure Vulnerabilities
The full path disclosure vulnerability can be exploited with a web browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The full path disclosure vulnerability can be exploited with a web browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Concrete5 Cross Site Scripting and Path Disclosure Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Concrete5 Cross Site Scripting and Path Disclosure Vulnerabilities
References:
References: