Justice Guestbook路径泄露漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1107260 漏洞类型 信息泄露
发布时间 2003-03-29 更新时间 2003-12-31
CVE编号 CVE-2003-1535 CNNVD-ID CNNVD-200312-267
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/22444
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-267
|漏洞详情
JusticeGuestbook1.3版本存在漏洞。远程攻击者借助到cfooter.php3的直接请求获取完整的安装路径,该漏洞在出错消息中泄漏路径。
|漏洞EXP
source: http://www.securityfocus.com/bid/7234/info

A path disclosure vulnerability has been reported for Guestbook. The issue occurs when a request is made to the cfooter.php3 PHP script page.

Access to sensitive filesystem information may aid an attacker in launching further attacks against a target system

http://hostname/jgb_eng_php3/cfooter.php3
|参考资料

来源:SECTRACK
名称:1006412
链接:http://www.securitytracker.com/id?1006412
来源:BID
名称:7234
链接:http://www.securityfocus.com/bid/7234
来源:BUGTRAQ
名称:20030329JusticeGuestbook1.3vulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/316745/30/25280/threaded
来源:SREASON
名称:3347
链接:http://securityreason.com/securityalert/3347
来源:SECUNIA
名称:8475
链接:http://secunia.com/advisories/8475