CVE-2012-5450 – CMS Made Simple 1.11.2 Cross Site Request Forgery
https://notcve.org/view.php?id=CVE-2012-5450
Cross-site request forgery (CSRF) vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) 1.11.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deld parameter. Una vulnerabilidad de falsificación de peticiones en sitios cruzados (CSRF) en lib/filemanager/ImageManager/images.php en CMS Made Simple (CMSMS) v1.11.2 y anteriores permite a atacantes remotos secuestrar la autenticación de los administradores de las peticiones que borran archivos de su elección a través del parámetro 'deld'. CMS Made Simple version 1.11.2 suffers from a cross site request forgery vulnerability. • http://archives.neohapsis.com/archives/bugtraq/2012-11/0035.html http://forum.cmsmadesimple.org/viewtopic.php?f=1&t=63545 http://packetstormsecurity.org/files/117951/CMS-Made-Simple-1.11.2-Cross-Site-Request-Forgery.html http://secunia.com/advisories/51185 http://viewsvn.cmsmadesimple.org/diff.php?repname=cmsmadesimple&path=%2Ftrunk%2Flib%2Ffilemanager%2FImageManager%2FClasses%2FImageManager.php&rev=8400&peg=8498 https://exchange.xforce.ibmcloud.com/vulnerabilities/79881 https://www.htbridge.com/advisory/HTB23121 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2012-1992 – CMS Made Simple 1.10.3 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2012-1992
Cross-site scripting (XSS) vulnerability in admin/edituser.php in CMS Made Simple 1.10.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter (aka the Email Address field in the Edit User template). Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en admin/edituser.php en CMS Made Simple v1.10.3 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro de correo electrónico (también conocido como el campo Dirección de correo electrónico del usuario en la plantilla de edición). CMS Made Simple versions 1.10.3 and below suffer from a cross site scripting vulnerability. • http://www.securityfocus.com/bid/52850 http://www.webapp-security.com/wp-content/uploads/2012/04/CMS-Made-Simple-1.10.3-XSS-Vulnerability2.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2010-4663
https://notcve.org/view.php?id=CVE-2010-4663
Unspecified vulnerability in the News module in CMS Made Simple (CMSMS) before 1.9.1 has unknown impact and attack vectors. Vulnerabilidad no especificada en el módulo News en CMS Made Simple (CMSMS) anterior a v1.9.1 tiene un impacto desconocido y vectores de ataque. • http://forum.cmsmadesimple.org/viewtopic.php?t=49245 http://openwall.com/lists/oss-security/2011/03/29/2 http://openwall.com/lists/oss-security/2011/03/30/9 •
CVE-2010-2797
https://notcve.org/view.php?id=CVE-2010-2797
Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the default_cms_lang parameter to an admin script, as demonstrated by admin/addbookmark.php, a different vulnerability than CVE-2008-5642. Una vulnerabilidad de salto de directorio en lib/translation.functions.php en CMS Made Simple antes de la versión v1.8.1 permite a atacantes remotos incluir y ejecutar archivos locales a través de un .. (Punto punto) en el parámetro default_cms_lang a un script de administración, tal y como se demuestra en admin/addbookmark.php. Se trata de una vulnerabilidad diferente a CVE-2008-5.642. • http://cross-site-scripting.blogspot.com/2010/07/cms-made-simple-18-local-file-inclusion.html http://secunia.com/advisories/40031 http://www.cmsmadesimple.org/2010/07/3/announcing-cms-made-simple-1-8-1-mankara http://www.openwall.com/lists/oss-security/2010/08/01/2 http://www.openwall.com/lists/oss-security/2010/08/02/8 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2010-3882
https://notcve.org/view.php?id=CVE-2010-3882
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.7.1 and earlier allow remote attackers to inject arbitrary web script or HTML via input to the (1) Add Pages, (2) Add Global Content, (3) Edit Global Content, (4) Add Article, (5) Add Category, (6) Add Field Definition, or (7) Add Shortcut module. Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados(XSS) en CMS Made Simple v1.7.1 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de la entrada de datos a los modulos (1) Agregar páginas (Add Pages), (2) Añadir contenido global (Add Global Content), (3) Editar Mundial Contenido(Edit Global Content), (4) Añadir artículo (Add Article), (5) Añadir una categoría (Add Category), (6) Agregar una definición de campo (Add Field Definition), o (7) Agregar acceso directo (Add Shortcut). • http://secunia.com/advisories/40031 http://security.bkis.com/multiple-vulnerabilities-in-cms-made-simple • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •