Document Title: =============== Evo CMS 2.1.0 - Multiple Web Vulnerabilities Release Date: ============= 2011-06-17 Vulnerability Laboratory ID (VL-ID): ==================================== 191 Product & Service Introduction: =============================== N/A Abstract Advisory Information: ============================== Vulnerability-Lab Team discovered multiple persistent & non-persistent Vulnerabilities on EVO s Content Management System 2.1. Vulnerability Disclosure Timeline: ================================== 2011-03-01: Vendor Notification 2011-00-00: Vendor Response/Feedback 2011-00-00: Vendor Fix/Patch 2011-06-10: Public or Non-Public Disclosure Discovery Status: ================= Published Affected Product(s): ==================== Exploitation Technique: ======================= Remote Severity Level: =============== Medium Technical Details & Description: ================================ 1.1 Multiple persistent Input Validation vulnerabilities are detected on EVO CMS 2.1.0. The persistent vulnerability allows an attacker to implement persistent malicious script codes on application-side. Attackers can manipulate Pool Voting requests on posts by implementing malicious script codes on topics. The successfully exploitation of the bug can lead to session hijacking & content request manipulation on server-side. Vulnerable Module(s): [+] Pool Topic [+] Story on News Topic Pictures: ../preview.title-xss.png ../pool-xss.png 1.2 A non-persistent cross site scripting vulnerability is detected on the all topics search of the application. The vulnerability allows to hijack customer sessions with high user inter action by cross site scripting requests. Vulnerable Module(s): [+] All Topics Search Pictures: ../search-topics-xss.png Proof of Concept (PoC): ======================= The vulnerabilities can be exploited by remote attackers with user inter-action. For example or demonstration ... 1.1 Vote on Pool
| Option 1: | |
| Option 2: | |
| Option 3: | |
| Option 4: | |
| Option 5: | |
| Option 6: | |
| Option 7: | |
| Option 8: | |
| Option 9: | |
| Option 10: | |
| Option 11: | |
| Option 12: |