packetstormsecurity.com
http://packetstormsecurity.com/files/136897/CMS-Made-Simple-Cache-Poisoning.html CVE-2016-2784
MEDIUM
CMS Made Simple < 1.12.1 / < 2.1.3 - Web Server Cache Poisoning
Record summary
CVE-2016-2784 has a selected CVSS score of 4.7 (medium); EIP currently links 1 catalogued exploit.
Description
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCMS Made Simple < 1.12.1 / < 2.1.3 - Web Server Cache PoisoningExploitDB exploitby Mickaël WalterNot analyzed1 file
References
720160506 CVE-2016-2784: CMS Made Simple < 2.1.3 & < 1.12.2 Web server Cache Poisoningmailing list
http://seclists.org/fulldisclosure/2016/May/15 cmsmadesimple.orgConfirmation
http://www.cmsmadesimple.org/2016/03/Announcing-CMSMS-1-12-2-kolonia cmsmadesimple.orgConfirmation
http://www.cmsmadesimple.org/2016/04/Announcing-CMSMS-2-1-3-Black-Point 20160504 CVE-2016-2784: CMS Made Simple < 2.1.3 & < 1.12.2 Web server Cache Poisoningmailing list
http://www.securityfocus.com/archive/1/538272/100/0/threaded nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-2784 39760exploit
https://www.exploit-db.com/exploits/39760