MidnightBSD

Advisories for squiz

CVE-2006-4635 MEDIUM

Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, to inject arbitrary PHP code via unspecified vectors related to the Equation attribute in Web_Extensions - Notitia (I/II). NOTE: due to lack of details, it is not clear whether this issue is file inclusion, static code injection, or another type of issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
squiz mysource_classic *
CVE-2006-5036 MEDIUM

MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
squiz mysource_classic *
squiz mysource_matrix *
CVE-2006-5037 MEDIUM

MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
squiz mysource_matrix 3.8.5
squiz mysource_matrix 3.10.1
squiz mysource_matrix 3.8.4
squiz mysource_matrix 3.8
squiz mysource_matrix 3.10
squiz mysource_matrix 3.8.3
squiz mysource_matrix 3.8.2
squiz mysource_matrix 3.8.6a
CVE-2010-4901 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
squiz mysource_matrix 3.28.3
CVE-2017-14196 MEDIUM

An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
squiz matrix *
squiz matrix 5.4.1.3
CVE-2017-14197 MEDIUM

An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Matrix WYSIWYG plugins.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
squiz matrix 5.4.0.3
squiz matrix 5.4.1.0
squiz matrix *
squiz matrix 5.4.1.2
squiz matrix 5.4.0.0
squiz matrix 5.4.0.2
squiz matrix 5.4.0.1
squiz matrix 5.4.1.1
CVE-2017-14198 MEDIUM

An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
squiz matrix 5.4.0.3
squiz matrix 5.4.1.0
squiz matrix *
squiz matrix 5.4.1.2
squiz matrix 5.4.0.0
squiz matrix 5.4.0.2
squiz matrix 5.4.0.1
squiz matrix 5.4.1.1