Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.803869
Categoría:Web application abuses
Título:BigTree CMS Multiple Vulnerabilities
Resumen:BigTree CMS is prone to multiple vulnerabilities.
Descripción:Summary:
BigTree CMS is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- Improper sanitation of user-supplied input passed via the
URL to the site/index.php script and 'module' parameter upon submission
to '/admin/developer/modules/views/add/index.php' script

- Cross-site request forgery (CSRF) vulnerability in
core/admin/modules/users/create.php and core/admin/modules/users/update.php

Vulnerability Impact:
Successful exploitation will allow remote attackers to insert arbitrary HTML
or script code, which will be executed in a user's browser session in the
context of an affected site, hijack user session or manipulate SQL queries
by injecting arbitrary SQL code.

Affected Software/OS:
BigTree CMS version 4.0 RC2 and prior.

Solution:
Update to version 4.0 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2013-4879
Bugtraq: 20130807 Multiple Vulnerabilities in BigTree CMS (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2013-08/0039.html
https://www.htbridge.com/advisory/HTB23165
http://osvdb.org/96007
XForce ISS Database: bigtreecms-cve20134879-sql-injection(86285)
https://exchange.xforce.ibmcloud.com/vulnerabilities/86285
Common Vulnerability Exposure (CVE) ID: CVE-2013-4880
http://osvdb.org/96008
XForce ISS Database: bigtreecms-cve20134880-xss(86287)
https://exchange.xforce.ibmcloud.com/vulnerabilities/86287
Common Vulnerability Exposure (CVE) ID: CVE-2013-5313
Common Vulnerability Exposure (CVE) ID: CVE-2013-4881
http://osvdb.org/96009
XForce ISS Database: bigtreecms-cve20134881-csrf(86286)
https://exchange.xforce.ibmcloud.com/vulnerabilities/86286
CopyrightCopyright (C) 2013 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.