Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Contenido CMS Unspecified Remote Command Execution Vulnerability

Contenido CMS is prone to an unspecified remote command execution vulnerability. This is due to a lack of proper sanitization of user-supplied input.

An attacker can exploit this vulnerability to execute arbitrary commands in the context of the Web server process. This may facilitate a compromise of the underlying system; other attacks are also possible.

It should be notes that the "allow_url_fopen" and "register_globals" PHP variables must be enabled to exploit this vulnerability.







 

Privacy Statement
Copyright 2008, SecurityFocus