The CMS content management system used by the US Army exposes major security vulnerabilities, which is standard configuration of the US Army

1 year ago (2024-01-26) Chief Editor
2 minutes
two hundred and forty-five
zero

An analysis report released today by the security company Edgescan shows that the content management system Concrete5 CMS contains a major vulnerability, which has been resolved by an updated version.

Guram Javakhishvili, senior information security consultant of Edgescan, disclosed that there is an RCE (remote code execution) security vulnerability in Concrete5, which can cause comprehensive damage to web applications and managed web servers after being exploited. "

Concrete5 is a free CMS system that can create websites and is famous for its ease of use. The main organizations using Concrete5 include GlobalSign, the US Army, REC and BASF.

Javakhishvili pointed out that RCE vulnerabilities are easy to exploit and can allow attackers to quickly gain full access to applications. During the security evaluation of this program, Edgescan found that it can modify the site configuration to upload PHP files and execute arbitrary commands. After adding, you can upload potentially malicious PHP code and execute system commands.

Through the "reverse shell" mechanism, an attacker can completely control the Web server, execute arbitrary commands on the server, and damage its integrity, availability, and confidentiality. In addition, the attacker can then attack other servers on the internal network.

Javakhishvili added that after investigation, Concrete 5 has now patched the vulnerability and released the latest stable version: 8.5.4.

Eoin Keary, CEO of Edgescan, said:

RCE may bring disaster to fragile web applications and web servers. In the Edgescan 2020 vulnerability statistics report, nearly 2% of vulnerabilities in the entire technology stack are attributed to RCE.

The survey reminds organizations to take regular actions to ensure the safety of their CMS systems. Edgescan recommended steps include keeping the installed script and CMS platform to the latest version, regularly backing up and subscribing to the regularly updated vulnerability list of CMS.

This article is written by: Chief Editor Published on Software Development of Little Turkey , please indicate the source for reprinting: //hongchengtech.cn/blog/4446.html
Kuke_WP editor
author

Related recommendations

1 year ago (2024-02-20)

What are the main contents of wms system in warehouse management

Original title: What does the wms system mainly embody in warehouse management? What does the wms system mainly embody in warehouse management? Warehouse management has standardized and intelligent process oriented management. A good warehouse management mechanism can improve the efficiency of warehouse managers, relieve their pressure, and complete efficient and accurate work. 1. Warehouse management is accompanied by the progress of the times
1 year ago (2024-02-18)

How to implement the mptt comment function of CMS content management system in Django?, Django management page

During the daily development of content related Web systems in the directory, whether it is Blog or CMS, if you need to add links to interact with users, you must need the comment function. Next, you can implement the comment reply function in Django based on Python's MPTT framework. Note: Because the user comment function will involve a
three hundred and ninety-four
zero
1 year ago (2024-02-18)

Best CMS content management system in 2022, good novel in 2021

Looking for the best CMS software to build your website? At a high level, CMS or content management systems can help you create functional websites without having to use code to build every page from scratch. However, different CMS software has different advantages and disadvantages, so you need to choose the tool that best suits your specific needs and budget. To help, we accept
four hundred and six
zero
1 year ago (2024-02-18)

Shenzhen promotes the access of 5G base station energy storage system to the virtual power plant management center in the city. Does the Shenzhen 5g government subsidize the flow package charge

Xinhua News Agency, Shenzhen, December 14 (Reporter Wang Feng) At the 2022 Carbon Peak Carbon Neutralization Forum and Shenzhen International Low Carbon City Forum held here in Shenzhen, Shenzhen Virtual Power Plant Management Center signed a cooperation agreement on virtual power plant construction with China Tower, China Telecom, China Mobile, China Unicom, Huawei Digital Energy and other units on the 13th, which will jointly promote the city's 5G base station energy storage system
three hundred and forty-three
zero
1 year ago (2024-02-18)

Common website cms content management system recommendation, common website cms content management software

CMS is the abbreviation of "Content Management System", which means "Content Management System" in Chinese. These systems have developed common website functions and provided them to users for download, greatly improving the efficiency of website construction. The most common functions of CMS are column management, article management, product management, picture management
three hundred and twenty-eight
zero

comment

0 people have participated in the review

Scan code to add WeChat

contact us

WeChat: Kuzhuti
Online consultation: