Holes in ActiveWeb Contentserver CMS
German service provider RedTeam Pentesting has published several security advisories to report vulnerabilities in the ActiveWeb Contentserver 5.x content management system. Despite defined restrictions, users with editor rights can, for instance, create documents in any location or may exploit an SQL injection vulnerability to inject arbitrary commands and to manipulate the database.
- ActiveWeb Contentserver CMS SQL Injection Management Interface, security advisory by RedTeam
- ActiveWeb Contentserver CMS Multiple Cross Site Scriptings, security advisory by RedTeam
- ActiveWeb Contentserver CMS Clientside Filtering of Page Editor Content, security advisory by RedTeam
- ActiveWeb Contentserver CMS Editor Permission Settings Problem, security advisory by RedTeam