OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA16169] Contrexx CMS Multiple Vulnerabilities

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Fri Jul 22 2005 - 05:52:28 CDT


----------------------------------------------------------------------

Bist Du interessiert an einem neuen Job in IT-Sicherheit?

Secunia hat zwei freie Stellen als Junior und Senior Spezialist in IT-
Sicherheit:
http://secunia.com/secunia_vacancies/

----------------------------------------------------------------------

TITLE:
Contrexx CMS Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA16169

VERIFY ADVISORY:
http://secunia.com/advisories/16169/

CRITICAL:
Moderately critical

IMPACT:
Cross Site Scripting, Manipulation of data, Exposure of system
information

WHERE:
From remote

SOFTWARE:
Contrexx CMS 1.x
http://secunia.com/product/5426/

DESCRIPTION:
Christopher Kunz has reported some vulnerabilities in Contrexx CMS,
which can be exploited by malicious people to conduct cross-site
scripting, script insertion and SQL injection attacks.

1) Input passed to the "votingoption" parameter in the poll module
and the "pId" parameter in the gallery module is not properly
sanitised before being used in a SQL query. This can be exploited to
manipulate SQL queries by injecting arbitrary SQL code.

2) Input passed to the "term" parameter in the search form is not
properly sanitised before being returned to users. This can be
exploited to execute arbitrary HTML and script code in a user's
browser session in context of a vulnerable site.

3) Input passed in certain blog entries (e.g. the title) is not
properly sanitised before being aggregated via the blog aggregation
module. This can be exploited to inject arbitrary HTML and script
code, which will be executed in an administrative user's browser
session in context of an affected site when the malicious user data
is viewed.

An issue has also been reported where the installation version is
included in the "config/version.xml" file.

The vulnerabilities have been reported in versions prior to 1.0.5.

SOLUTION:
Update to version 1.0.5.
http://www.contrexx.com/index.php?section=media1&path=/media/archive1/Opensource/

PROVIDED AND/OR DISCOVERED BY:
Christopher Kunz, Hardened PHP Project.

ORIGINAL ADVISORY:
Hardened PHP Project:
http://www.hardened-php.net/advisory_112005.59.html

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------