FerretCMS Multiple Security Vulnerabilities
BID:72287
Info
FerretCMS Multiple Security Vulnerabilities
| Bugtraq ID: | 72287 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-1373 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2015 12:00AM |
| Updated: | Feb 04 2015 12:02AM |
| Credit: | Steffen Rösemann |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
FerretCMS Multiple Security Vulnerabilities
FerretCMS is prone to the following security vulnerabilities:
1. Multiple SQL-Injection vulnerabilities
2. A cross-site scripting vulnerability
3. Multiple HTML-Injection vulnerabilities
4. An arbitrary file upload vulnerability
Exploiting these vulnerabilities could allow an attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database and to upload arbitrary files.
FerretCMS 1.0.4-alpha is vulnerable; other versions may also be affected.
FerretCMS is prone to the following security vulnerabilities:
1. Multiple SQL-Injection vulnerabilities
2. A cross-site scripting vulnerability
3. Multiple HTML-Injection vulnerabilities
4. An arbitrary file upload vulnerability
Exploiting these vulnerabilities could allow an attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database and to upload arbitrary files.
FerretCMS 1.0.4-alpha is vulnerable; other versions may also be affected.
Exploit / POC
FerretCMS Multiple Security Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user into following a malicious URI.
Attackers can use a browser to exploit these issues. To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user into following a malicious URI.
Solution / Fix
FerretCMS Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
FerretCMS Multiple Security Vulnerabilities
References:
References: