Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.804640
Categoría:Web application abuses
Título:ZeroCMS Privilege Escalation & SQL Injection Vulnerabilities
Resumen:ZeroCMS is prone to privilege escalation, cross-site scripting and sql injection vulnerabilities.
Descripción:Summary:
ZeroCMS is prone to privilege escalation, cross-site scripting and sql injection vulnerabilities.

Vulnerability Insight:
Input passed via the 'article_id' GET
parameter to zero_view_article.php script, 'access_level' POST parameter to
zero_transact_user.php script, 'Full Name' field to zero_user_account.php
script and 'article_id' POST parameter to the zero_transact_article.php
script is not properly sanitised before being used.

Vulnerability Impact:
Successful exploitation will allow
attacker to gain unauthorized privileges and manipulate SQL queries in the
backend database allowing for the manipulation or disclosure of arbitrary
data, execute arbitrary HTML and script code in a user's browser session in
the context of an affected site.

Affected Software/OS:
ZeroCMS version 1.0

Solution:
No known solution was made available for at least one year
since the disclosure of this vulnerability. Likely none will be provided anymore. General solution
options are to upgrade to a newer release, disable respective features, remove the product or
replace the product by another one.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2014-4034
BugTraq ID: 67953
http://www.securityfocus.com/bid/67953
http://www.exploit-db.com/exploits/33702
http://seclists.org/fulldisclosure/2015/Feb/4
http://packetstormsecurity.com/files/127005/ZeroCMS-1.0-SQL-Injection.html
http://packetstormsecurity.com/files/130192/ZeroCMS-1.3.3-SQL-Injection.html
http://sroesemann.blogspot.de/2015/01/report-for-advisory-sroeadv-2015-14.html
http://sroesemann.blogspot.de/2015/01/sroeadv-2015-13.html
http://sroesemann.blogspot.de/2015/02/addition-for-advisory-sroeadv-2015-14.html
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5186.php
http://seclists.org/oss-sec/2015/q1/379
http://seclists.org/oss-sec/2015/q1/380
http://secunia.com/advisories/59182
XForce ISS Database: zerocms-zeroviewarticle-script-sql-injection(100588)
https://exchange.xforce.ibmcloud.com/vulnerabilities/100588
Common Vulnerability Exposure (CVE) ID: CVE-2014-4195
BugTraq ID: 68246
http://www.securityfocus.com/bid/68246
http://packetstormsecurity.com/files/127262/ZeroCMS-1.0-Cross-Site-Scripting.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-4194
BugTraq ID: 68134
http://www.securityfocus.com/bid/68134
http://packetstormsecurity.com/files/127164/ZeroCMS-1.0-SQL-Injection.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-4710
http://www.exploit-db.com/exploits/34170
http://packetstormsecurity.com/files/127634/ZeroCMS-1.0-Cross-Site-Scripting.html
https://community.qualys.com/blogs/securitylabs/2014/07/24/yet-another-zerocms-cross-site-scripting-vulnerability-cve-2014-4710
CopyrightCopyright (C) 2014 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.