Summary
This host is running Baby Gekko CMS and is
prone to multiple vulnerabilities.
Impact
Successful exploitation will allow remote
attackers to inject or manipulate SQL queries in the back-end database and execute arbitrary HTML and script code in a user's browser session in the context of an affected site.
Impact Level: Application
Solution
Upgrade to 1.2.2f, 1.2.4, or later. For
updates refer to http://www.schlix.com
Insight
Multiple errors exists due to,
- Insufficient validation of input passed via the 'keyword', 'query' and 'id' parameters to /admin/index.php script.
- Insufficient validation of input passed via the 'app' parameter to index.php script.
- Insufficient validation of input passed via the 'username' and 'password' HTTP POST parameters to the index.php script.
Affected
Baby Gekko CMS before version 1.2.2f
Detection
Send a crafted data via HTTP GET
request and check whether it is able to read cookie or not.
References
Severity
Classification
-
CVE CVE-2012-5698, CVE-2012-5699, CVE-2012-5700 -
CVSS Base Score: 9.0
AV:N/AC:L/Au:N/C:C/I:P/A:P
Related Vulnerabilities