Anchor CMS 'comment.php' Mail Header Injection Vulnerability
BID:71020
Info
Anchor CMS 'comment.php' Mail Header Injection Vulnerability
| Bugtraq ID: | 71020 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9182 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2014 12:00AM |
| Updated: | Dec 05 2014 12:56AM |
| Credit: | Paulos Yibelo |
| Vulnerable: |
Anchor CMS 2012 Anchor CMS 0.6-14-ga85d0a0 Anchor CMS 2012 Anchor CMS 0.6-0.4 |
| Not Vulnerable: | |
Discussion
Anchor CMS 'comment.php' Mail Header Injection Vulnerability
Anchor CMS is prone to a header-injection vulnerability because it fails to sufficiently sanitize input.
A successful attack may allow attackers to insert arbitrary email headers into an HTTP response; this may aid in launching further attacks.
Anchor CMS 0.9.2 and prior are vulnerable.
Anchor CMS is prone to a header-injection vulnerability because it fails to sufficiently sanitize input.
A successful attack may allow attackers to insert arbitrary email headers into an HTTP response; this may aid in launching further attacks.
Anchor CMS 0.9.2 and prior are vulnerable.
Exploit / POC
Anchor CMS 'comment.php' Mail Header Injection Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
Anchor CMS 'comment.php' Mail Header Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Anchor CMS 'comment.php' Mail Header Injection Vulnerability
References:
References:
- Anchor CMS Homepage (Anchor CMS 2012)