Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-4341

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2011-4341
Last Modified 13 Feb 2012 10:06:08
Published 12 Feb 2012 05:55:01
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-4341

Summary

Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author permissions to execute arbitrary SQL commands via the filter parameter to (1) symphony/publish/comments or (2) symphony/publish/images. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks via error messages. NOTE: some of these details are obtained from third party information.

Vulnerable Systems

Application

  • Symphony-cms Symphony Cms 2.2.3


References

CONFIRM - https://github.com/symphonycms/symphony-2/commit/476e4926e2773588eab10dd3036f27e1411521b5

XF - symphony-filter-sql-injection(71105)

OSVDB - 76884

MLIST - [oss-security] 20111122 Re: CVE-request: Symphony CMS Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (NS-11-008)

MISC - http://www.mavitunasecurity.com/xss-and-sql-injection-vulnerabilities-in-symphony-cms/

CONFIRM - http://symphony-cms.com/download/releases/version/2.2.4/

SECUNIA - 46663

BUGTRAQ - 20111101 XSS and SQL Injection Vulnerabilities on Symphony CMS 2.2.3

MISC - http://packetstormsecurity.org/files/view/106493/symphonycms-sqlxss.txt


Last Updated: 27 May 2016 10:57:26