GetSimple CMS Multiple Vulnerabilities
BID:70084
Info
GetSimple CMS Multiple Vulnerabilities
| Bugtraq ID: | 70084 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2014 12:00AM |
| Updated: | Sep 23 2014 12:00AM |
| Credit: | Vadodil Joel Varghese |
| Vulnerable: |
Cagintranetworks GetSimple CMS 3.3.3 |
| Not Vulnerable: | |
Discussion
GetSimple CMS Multiple Vulnerabilities
GetSimple CMS is prone to the following vulnerabilities:
1. A cross-site request forgery vulnerability
2. A clickjacking vulnerability
3. Multiple cross-site scripting vulnerabilities
Attackers can exploit these issues by tricking a victim into visiting a malicious webpage consisting of specially crafted script code designed to perform some action on the attacker's behalf and to execute arbitrary script code to steal cookie-based authentication credentials. Successful exploits may allow an remote attacker to gain unauthorized access to the affected application.
GetSimple CMS 3.3.3 is vulnerable; other versions may also be affected.
GetSimple CMS is prone to the following vulnerabilities:
1. A cross-site request forgery vulnerability
2. A clickjacking vulnerability
3. Multiple cross-site scripting vulnerabilities
Attackers can exploit these issues by tricking a victim into visiting a malicious webpage consisting of specially crafted script code designed to perform some action on the attacker's behalf and to execute arbitrary script code to steal cookie-based authentication credentials. Successful exploits may allow an remote attacker to gain unauthorized access to the affected application.
GetSimple CMS 3.3.3 is vulnerable; other versions may also be affected.