|
[Japanese]
|
JVNDB-2012-000043
|
baserCMS vulnerable to session management
|
baserCMS contains a vulnerability in session management.
baserCMS is an open-source Contents Management System (CMS). baserCMS contains a vulnerability in session management.
|
Base Metrics:
4.0 (Medium)
[IPA Score]
- Access Vector: Network
- Access Complexity: High
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: None
|
|
|
CATCH UP
- BaserCMS 1.6.15 and earlier
|
|
If a web server is hosting several websites, and baserCMS are installed on the respective websites, an administrator of a baserCMS can access baserCMS instance of the other website within the same hosting server.
|
[Update the software]
Update to the latest version according to the information provided by the developer.
[Apply a workaround]
The following workaround may mitigate the affects of this vulnerability.
* Rewrite app/config/core.php
For more information, refer to the developer's website.
|
CATCH UP
|
- No Mapping(CWE-noinfo) [IPA Evaluation]
|
- CVE-2012-1248
|
- JVN : JVN#53465692
- National Vulnerability Database (NVD) : CVE-2012-1248
|
[2012/05/15]
Web page was published
|