Web Application Security
Ektron CMS Take Over - Hijacking Accounts Jan 30 2014 09:08AM
Mark Litchfield (mark securatary com)
I have detailed a vulnerability within Ektron CMS that allows an
unauthenticated user to hijack any account. The clear targets of choice
for this CMS would be the builtin or admin account.

Whilst I found this issue back in 2012, it appears that around 65% are
still vulnerable and should be patching their systems. I did notify
Ektron about this and I know a patch was made, but I did not bother
releasing an advisory. Why now... Way to many sites have still not
updated, this could be in part because it appears there is no mention of
the issue on Ektrons site. Security issues are always a good incentive
to adopt patches. The other reason being, I have a new vulnerability in
their fix and I will follow up with this shortly.

As usual, full details can be found here with Screen shots -

All the best


This list is sponsored by Cenzic
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now!

[ reply ]


Privacy Statement
Copyright 2010, SecurityFocus