vendor:
Baby Gekko CMS
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Multiple Stored Cross-Site Scripting Vulnerabilities
79
CWE
Product Name: Baby Gekko CMS
Affected Version From: 1.1.5c
Affected Version To: 1.1.5c
Patch Exists: YES
Related CWE: N/A
CPE: a:babygekko:baby_gekko_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN), Apache 2.2.21, PHP 5.3.9, MySQL 5.5.20
2012
Baby Gekko CMS v1.1.5c Multiple Stored Cross-Site Scripting Vulnerabilities
Baby Gekko CMS suffers from multiple stored (post-auth) XSS vulnerabilities and path disclosure issues when parsing user input to several parameters via GET and POST method. Attackers can exploit this weakness to execute arbitrary HTML and script code in a user's browser session or disclose the full installation path of the affected CMS.
Mitigation:
Upgrade to Baby Gekko CMS version 1.2.0 or later.