Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.804640
Category:Web application abuses
Title:ZeroCMS Privilege Escalation & SQL Injection Vulnerabilities
Summary:ZeroCMS is prone to privilege escalation, cross-site scripting and sql injection vulnerabilities.
Description:Summary:
ZeroCMS is prone to privilege escalation, cross-site scripting and sql injection vulnerabilities.

Vulnerability Insight:
Input passed via the 'article_id' GET
parameter to zero_view_article.php script, 'access_level' POST parameter to
zero_transact_user.php script, 'Full Name' field to zero_user_account.php
script and 'article_id' POST parameter to the zero_transact_article.php
script is not properly sanitised before being used.

Vulnerability Impact:
Successful exploitation will allow
attacker to gain unauthorized privileges and manipulate SQL queries in the
backend database allowing for the manipulation or disclosure of arbitrary
data, execute arbitrary HTML and script code in a user's browser session in
the context of an affected site.

Affected Software/OS:
ZeroCMS version 1.0

Solution:
No known solution was made available for at least one year
since the disclosure of this vulnerability. Likely none will be provided anymore. General solution
options are to upgrade to a newer release, disable respective features, remove the product or
replace the product by another one.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-4034
BugTraq ID: 67953
http://www.securityfocus.com/bid/67953
http://www.exploit-db.com/exploits/33702
http://seclists.org/fulldisclosure/2015/Feb/4
http://packetstormsecurity.com/files/127005/ZeroCMS-1.0-SQL-Injection.html
http://packetstormsecurity.com/files/130192/ZeroCMS-1.3.3-SQL-Injection.html
http://sroesemann.blogspot.de/2015/01/report-for-advisory-sroeadv-2015-14.html
http://sroesemann.blogspot.de/2015/01/sroeadv-2015-13.html
http://sroesemann.blogspot.de/2015/02/addition-for-advisory-sroeadv-2015-14.html
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5186.php
http://seclists.org/oss-sec/2015/q1/379
http://seclists.org/oss-sec/2015/q1/380
http://secunia.com/advisories/59182
XForce ISS Database: zerocms-zeroviewarticle-script-sql-injection(100588)
https://exchange.xforce.ibmcloud.com/vulnerabilities/100588
Common Vulnerability Exposure (CVE) ID: CVE-2014-4195
BugTraq ID: 68246
http://www.securityfocus.com/bid/68246
http://packetstormsecurity.com/files/127262/ZeroCMS-1.0-Cross-Site-Scripting.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-4194
BugTraq ID: 68134
http://www.securityfocus.com/bid/68134
http://packetstormsecurity.com/files/127164/ZeroCMS-1.0-SQL-Injection.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-4710
http://www.exploit-db.com/exploits/34170
http://packetstormsecurity.com/files/127634/ZeroCMS-1.0-Cross-Site-Scripting.html
https://community.qualys.com/blogs/securitylabs/2014/07/24/yet-another-zerocms-cross-site-scripting-vulnerability-cve-2014-4710
CopyrightCopyright (C) 2014 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.