Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.804225
Category:Web application abuses
Title:GetSimple CMS 3.1.x / 3.2.x Multiple Vulnerabilities
Summary:GetSimple CMS is prone to multiple vulnerabilities.
Description:Summary:
GetSimple CMS is prone to multiple vulnerabilities.

Vulnerability Insight:
Flaw exists in upload.php, theme.php, pages.php, settings.php
and index.php scripts, which fail to properly sanitize user-supplied input to 'path', 'err',
'error' and 'success' parameter and 'Custom Permalink Structure', 'Display name', 'Email Address'
fields.

Vulnerability Impact:
Successful exploitation will allow remote attackers to inject
HTML code or steal the victim's cookie-based authentication credentials.

Affected Software/OS:
GetSimple CMS 3.1, 3.1.2, 3.2.3 are known to be affected. Other
versions may also be affected.

Solution:
No known solution was made available for at least one year
since the disclosure of this vulnerability. Likely none will be provided anymore. General solution
options are to upgrade to a newer release, disable respective features, remove the product or
replace the product by another one.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-6621
BugTraq ID: 53501
http://www.securityfocus.com/bid/53501
http://packetstormsecurity.com/files/124711
http://packetstormsecurity.org/files/112643/GetSimple-CMS-3.1-Cross-Site-Scripting.html
http://www.vulnerability-lab.com/get_content.php?id=521
http://secunia.com/advisories/49137
XForce ISS Database: getsimplecms-multiple-xss(75535)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75535
XForce ISS Database: getsimplecms-settings-xss(75534)
https://exchange.xforce.ibmcloud.com/vulnerabilities/75534
Common Vulnerability Exposure (CVE) ID: CVE-2013-7243
http://osvdb.org/101922
XForce ISS Database: getsimplecms-cve20137243-xss(90191)
https://exchange.xforce.ibmcloud.com/vulnerabilities/90191
CopyrightCopyright (C) 2014 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.