Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.804268
Category:Web application abuses
Title:CM3 AcoraCMS Multiple XSS, CSRF and Open Redirect Vulnerabilities
Summary:CM3 AcoraCMS is prone to multiple XSS, CSRF and url redirection vulnerabilities.
Description:Summary:
CM3 AcoraCMS is prone to multiple XSS, CSRF and url redirection vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- Insufficient validation of user-supplied input via 'username', 'url', 'qstr'
passed to login/default.asp

- Insufficient validation of the 'l' parameter upon submission to track.aspx
script.

- insufficient measures for confirmation of sensitive transactions.

Vulnerability Impact:
Successful exploitation will allow attackers to redirect victim from the
intended legitimate web site to an arbitrary web site, trick the users into
performing an unspecified action in the context of their session with the
application and execute arbitrary script code in a user's browser session
in context of an affected site.

Affected Software/OS:
CM3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other
versions

Solution:
No known solution was made available for at least one year
since the disclosure of this vulnerability. Likely none will be provided anymore. General solution
options are to upgrade to a newer release, disable respective features, remove the product or
replace the product by another one.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-4722
http://packetstormsecurity.com/files/122954/CM3-AcoraCMS-XSS-CSRF-Redirection-Disclosure.html
http://www.digitalsec.net/stuff/explt+advs/CM3.AcoraCMS.v6.txt
http://osvdb.org/96661
Common Vulnerability Exposure (CVE) ID: CVE-2013-4723
http://osvdb.org/96662
Common Vulnerability Exposure (CVE) ID: CVE-2013-4724
http://osvdb.org/96664
Common Vulnerability Exposure (CVE) ID: CVE-2013-4725
Common Vulnerability Exposure (CVE) ID: CVE-2013-4726
http://osvdb.org/96665
Common Vulnerability Exposure (CVE) ID: CVE-2013-4727
http://osvdb.org/96666
Common Vulnerability Exposure (CVE) ID: CVE-2013-4728
http://osvdb.org/96667
CopyrightCopyright (C) 2014 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.