
David Vieira-Kurz has discovered some vulnerabilities in Simploo CMS, which can be exploited by malicious people to compromise a vulnerable system. Input passed to the "ftpserver" parameter in "/sicore/updates/optionssave" is not properly sanitised before being used. This can be exploited to inject and execute arbitrary PHP code via a specially crafted parameter value.
Unaltered electronic reproduction of this advisory is permitted. For all other reproduction or publication, in printing or otherwise, contact us for permission. Use of the advisory constitutes acceptance for use in an "as is" condition. All warranties are excluded. In no event shall MajorSecurity be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if MajorSecurity has been advised of the possibility of such damages.