Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

November 2nd, 2011, 07:34 GMT · By Eduard Kovacs

BLOG

Symphony CMS Vulnerable to XSS and SQL Injection Attacks

SHARE:

Adjust text size:

The old versions of Symphony CMS are highly vulnerable Enlarge picture - The old versions of Symphony CMS are highly vulnerable
Researchers warn users that critical vulnerabilities were discovered in Symphony CMS 2.2.3, possibly affecting the previous versions.

Security Focus informs us that some variants of the XSLT-powered open source content management systems are affected by several XSS and SQL Injection weaknesses that could allow an attacker to execute dynamic scripts or to mount attacks such as reading, updating or deleting arbitrary data or tables from the database and executing commands.

Symphony users are advised to update the software to the latest version to make sure they're protected against malicious operations.

The flaws were discovered with Netsparker, a web application that tests websites for vulnerabilities that could leave them exposed in front of hackers.

Symphony CMS 2.2.4 is available for download here

TELL US WHAT YOU THINK:

717 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Security Update for Adobe Flash Player 10.3

Hackers Publish Vulnerabilities in US Law Enforcement Websites

Google Patches 18 Security Holes with the Release of Chrome 15

XML Encryption Flaw Leaves E-Commerce Exposed

READER COMMENTS:


Comment #1 by: fyi on 05 Nov 2011, 14:56 UTC reply to this comment

FWIW, these vulnerabilities required the attacker to be logged into the administration interface. And if you've got a malicious user logged into your admin, you've got bigger problems...

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM