News
Contributed by: Lauren Gerber
Date: July 7, 2009
Welcome to yet another article about specific computer security vulnerabilities. Once again, I am here to bring you the latest news with regard to chaotic vulnerabilities. The vulnerabilities which I shall be talking about today relate to Campsite. It has recently been reported that Campsite is vulnerable to various multiple vulnerabilities with the inclusion of cross site scripting, local as well as remote file inclusion issues. Campsite is wonderful open source software which is geared for web publishing. It brings specific written content to the online world. It is often used by various media companies in order to produce online versions of their work and publications. It is the only open source system which was designed to work in a similar style to that of magazines and newspapers. This software is compatible with any web browser with the inclusion of Apple Safe:SAFARI.EXE, Google Chrome:chrome.exe as well as Mozilla Firefox:channel-prefs.js. If these vulnerabilities are exploited, malicious characters will be able to gain cookie based credentials which are authenticated. They may also be able to obtain various other confidential information. This is not the only thing they are able to get their hands on. They may also be able to execute manipulated PHP code in the browsers of users who have no clue what is going on. The other risks are that the vulnerabilities may allow for malicious characters to actually compromise the machines of users as well as applications of their choice. Malicious individuals are able to exploit these issues via chosen web browsers. If malicious attackers chose to exploit the cross site scripting vulnerability then it is vital for the attacker to first convince a user to go to a manipulated link. The big question now is, what versions of Campsite do these vulnerabilities affect? The version of Campsite that is affected is version 3.3.0 RC1. The risks are very high that other versions may also be affected by these vulnerabilities. All users are advised to keep their software updated to the latest versions where possible. |
|||||
Software Downloads




User Comments