Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.804268
Categoría:Web application abuses
Título:CM3 AcoraCMS Multiple XSS, CSRF and Open Redirect Vulnerabilities
Resumen:CM3 AcoraCMS is prone to multiple XSS, CSRF and url redirection vulnerabilities.
Descripción:Summary:
CM3 AcoraCMS is prone to multiple XSS, CSRF and url redirection vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- Insufficient validation of user-supplied input via 'username', 'url', 'qstr'
passed to login/default.asp

- Insufficient validation of the 'l' parameter upon submission to track.aspx
script.

- insufficient measures for confirmation of sensitive transactions.

Vulnerability Impact:
Successful exploitation will allow attackers to redirect victim from the
intended legitimate web site to an arbitrary web site, trick the users into
performing an unspecified action in the context of their session with the
application and execute arbitrary script code in a user's browser session
in context of an affected site.

Affected Software/OS:
CM3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other
versions

Solution:
No known solution was made available for at least one year
since the disclosure of this vulnerability. Likely none will be provided anymore. General solution
options are to upgrade to a newer release, disable respective features, remove the product or
replace the product by another one.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2013-4722
http://packetstormsecurity.com/files/122954/CM3-AcoraCMS-XSS-CSRF-Redirection-Disclosure.html
http://www.digitalsec.net/stuff/explt+advs/CM3.AcoraCMS.v6.txt
http://osvdb.org/96661
Common Vulnerability Exposure (CVE) ID: CVE-2013-4723
http://osvdb.org/96662
Common Vulnerability Exposure (CVE) ID: CVE-2013-4724
http://osvdb.org/96664
Common Vulnerability Exposure (CVE) ID: CVE-2013-4725
Common Vulnerability Exposure (CVE) ID: CVE-2013-4726
http://osvdb.org/96665
Common Vulnerability Exposure (CVE) ID: CVE-2013-4727
http://osvdb.org/96666
Common Vulnerability Exposure (CVE) ID: CVE-2013-4728
http://osvdb.org/96667
CopyrightCopyright (C) 2014 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.