|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> CGI abuses >> toendaCMS < 0.6.2.1 Multiple Vulnerabilities Vulnerability Assessment Details
|
toendaCMS < 0.6.2.1 Multiple Vulnerabilities |
||
Checks for multiple vulnerabilities in toendaCMS < 0.6.2.1 Detailed Explanation for this Vulnerability Assessment Summary : The remote web server contains a PHP application that is affected by multiple flaws. Description : The remote host is running toendaCMS, a content management and weblogging system written in PHP. The version of toendaCMS installed on the remote host permits an unauthenticated attacker to read arbitrary files by manipulating the 'id_user' parameter of the 'engine/admin/admin.php' script. In addition, it stores account and session data files in XML mode without protection under the web root a possible hacker can download these and gain access to sensitive information such as password hashes. Finally, if a possible hacker gains administrative access, he can upload files with arbitrary PHP code through the gallery scripts and execute them subject to the rights of the web server user id. See also : http://www.sec-consult.com/227.html http://www.toenda.com/en/?id=newsmanager&s=nano&news=9cc84a8aa7 Solution : Upgrade to toendaCMS version 0.6.2.1 or later. Network Security Threat Level: Medium / CVSS Base Score : 4.2 (AV:R/AC:L/Au:R/C:P/I:P/A:P/B:N) Networks Security ID: 15348, 15351 Vulnerability Assessment Copyright: This script is Copyright (C) 2005-2006 Tenable Network Security |
||
Cables, Connectors |
DT8XJ Dell Intel DC S3700 800GB SATA 6Gb/s 2.5" SSD 0DT8XJ SSDSC2BA800G3R
$59.00
SanDisk 1TB SSD Plus, Internal Solid State Drive - SDSSDA-1T00-G26
$74.99
Samsung 870 EVO Series 500GB 2.5" SATA III Internal SSD MZ-77E500B/AM New Sealed
$59.00
09F3GY DELL /Intel DC S3610 Series SSDSC2BX800G4R 800GB 2.5 inch SATA3 SSD 9F3GY
$89.00
Crucial BX500 240GB Internal SSD,Micron 3D NAND SATA CT240BX500SSD1 - OEM item
$16.99
Netac 1TB 2TB 512GB Internal SSD 2.5'' SATA III 6Gb/s Solid State Drive lot
$13.99
Patriot P210 128GB 256GB 512GB 1TB 2TB 2.5" SATA 3 6GB/s Internal SSD PC/MAC Lot
$14.99
Intel Optane Memory M10 SSD M.2 2280 16GB MEMPEK1J016GA PCIe 3.0 3D Xpoint NVMe
$5.99
Fanxiang SSD 512GB 1TB 2TB 4TB 2.5'' SSD SATA III Internal Solid State Drive lot
$198.99
Fanxiang 256GB 512GB 1TB 2TB 4TB Internal SSD 2.5" SATA III 6GB/s for PC/MAC Lot
$197.99
|
||
No Discussions have been posted on this vulnerability. |