OSVDB ID: 13130

Title: CMSimple CMS Search/Guestbook Modules XSS Vulnerability

Info

Disclosure

Jan 18, 2005

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

CMSimple Content Management System contains flaws that allow a remote cross site scripting attack. These flaws exist because the application does not validate user-supplied variables upon submission to the search and guestbook modules. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Rumored / Private
Disclosure: OSVDB Verified

Solution

Upgrade to version 2.4 Beta 5 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

CMSimple

Content Management System

1.0
1.1
1.2
Beta 1
2.0 Beta 1
2.0 Beta 2
2.0 Beta 3
2.0 Beta 4
2.2
2.3 Beta 1
2.3 Beta 2
2.3 Beta 3
2.3 Beta 4
2.3 Beta 5
2.3
2.4 Beta 1
2.4 Beta 2
2.4 Beta 3
2.4 Beta 4
2.4 beta 5
beta 2
1.3 beta 1
1.3 beta 2
2.1
2.4 Beta
2.2 Beta 1
2.2 Beta 2
2.2 Beta 3
2.2 Beta 4

References

Credit

  • CMSimple - CMSimple


Direct URL: http://osvdb.org/36218