[Japanese]
|
JVNDB-2017-000203
|
Multiple vulnerabilities in baserCMS
|
baserCMS provided by baserCMS Users Community contains multiple vulnerabilities listed below.
* SQL injection (CWE-89) - CVE-2017-10842
* Arbitary files may be deleted - CVE-2017-10843
* Arbitary PHP code execution - CVE-2017-10844
Shoji Baba reported the vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 7.3 (High) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low
CVSS V2 Severity: Base Metrics 7.5 (High) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2017-10842.
|
CVSS V3 Severity:
Base Metrics:
7.3 (High) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low
CVSS V2 Severity:Base Metrics:
7.5 (High)
[IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2017-10843.
|
CVSS V3 Severity:
Base Metrics:
6.3 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low
CVSS V2 Severity:Base Metrics:
7.5 (High)
[IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2017-10844.
|
|
baserCMS Users Community
- baserCMS version 3.0.14 and earlier
- baserCMS version 4.0.5 and earlier
|
|
* A remote attacker may execute arbitrary SQL command to create files or obtain or alter information stored in the database. - CVE-2017-10842
* A remote attacker may obtain or delete arbitrary files on the system. - CVE-2017-10843
* A user may execute arbitrary PHP code on the server. - CVE-2017-10844
|
[Update the Software]
Update to the latest version according to the information provided by the developer.
[Apply the Patch]
Patches have been released. For more information, refer to "How to Apply the Patches".
|
baserCMS Users Community
|
- Improper Input Validation(CWE-20) [IPA Evaluation]
- SQL Injection(CWE-89) [IPA Evaluation]
- Code Injection(CWE-94) [IPA Evaluation]
|
- CVE-2017-10842
- CVE-2017-10843
- CVE-2017-10844
|
- JVN : JVN#78151490
- National Vulnerability Database (NVD) : CVE-2017-10842
- National Vulnerability Database (NVD) : CVE-2017-10843
- National Vulnerability Database (NVD) : CVE-2017-10844
|
- [2017/08/25]
Web page was published
- [2018/02/28]
References : Contents were added
|