|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
Exponent CMS contains a flaw that may allow a malicious user to run arbitrary PHP code. The issue is triggered due to the Banner and Image modules parsing user supplied PHP code. It is possible that the flaw may allow arbitrary code injection resulting in a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Rumored / Private
OSVDB:
Web Related
|
|
Solution |
Upgrade to version 0.96.5 RC 1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Exponent CMS
 |
0.96 .4 |
0.96 .3 |
0.96 .2 |
0.96 .1 |
0.96 |
0.95.x |
0.94.x |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|