ASPTicker news.mdb敏感信息泄漏漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1116940 漏洞类型 权限许可和访问控制
发布时间 2008-12-05 更新时间 2008-12-16
CVE编号 CVE-2008-5603 CNNVD-ID CNNVD-200812-288
漏洞平台 ASP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/7359
https://www.securityfocus.com/bid/84640
https://cxsecurity.com/issue/WLB-2008120155
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200812-288
|漏洞详情
ASPTicker是一款用ASP实现的滚动新闻管理系统。ASPTicker1.0版本在网根下储存敏感信息并未给予足够的访问控制,这会允许远程攻击者可以借助向news.mdb提交一个直接的请求,下载数据库文件。
|漏洞EXP
[~] ASPTicker 1.0 DD Remote Vuln.
[~]
[~] ----------------------------------------------------------
[~] Discovered By: ZoRLu   msn: trt-turk@hotmail.com
[~]
[~] Home: www.z0rlu.blogspot.com
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~] -----------------------------------------------------------


exp for demo: ( DD )

http://demo.merlix.com/ticker/news.mdb

[~]----------------------------------------------------------------------
[~] Greetz tO: str0ke 
[~]
[~] yildirimordulari.org  &  darkc0de.com
[~]
[~]----------------------------------------------------------------------

# milw0rm.com [2008-12-05]
|受影响的产品
Aspapps Aspticker 1.0
|参考资料

来源:XF
名称:aspticker-news-info-disclosure(47143)
链接:http://xforce.iss.net/xforce/xfdb/47143
来源:MILW0RM
名称:7359
链接:http://www.milw0rm.com/exploits/7359
来源:SREASON
名称:4762
链接:http://securityreason.com/securityalert/4762
来源:SECUNIA
名称:23573
链接:http://secunia.com/advisories/23573