Sambar Server 5.x - Information Disclosure

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1053791 漏洞类型
发布时间 2003-03-27 更新时间 2003-03-27
CVE编号 N/A CNNVD-ID N/A
漏洞平台 Windows CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/22434
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/7207/info

An information disclosure vulnerability has been reported for Sambar Server. The vulnerability exists in some files existing in Sambar Server's cgi-bin directory.

An attacker can exploit this vulnerability by making a request for these files. This will result in Sambar Server returning potentially sensitive information.

An attacker can use the information obtained in this manner to launch further attacks against a vulnerable host. 

http://[target]/cgi-bin/environ.pl
http://[target]/cgi-bin/testcgi.exe