Nuked-Klan远程信息泄露漏洞

Nuked-Klan远程信息泄露漏洞

漏洞ID 1107217 漏洞类型 跨站脚本
发布时间 2003-02-23 更新时间 2003-12-31
图片[1]-Nuked-Klan远程信息泄露漏洞-安全小百科CVE编号 CVE-2003-1371
图片[2]-Nuked-Klan远程信息泄露漏洞-安全小百科CNNVD-ID CNNVD-200312-416
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/22277
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-416
|漏洞详情
Nuked-klan是一款由PHP编写的脚本。Nuked-klan不正确过滤用户提供的URI参数,远程攻击者可以利用这个漏洞执行部分PHP函数,获得大量系统敏感信息。由于Nuked-klan对模块’Team’、’News’和’Lien’的请求缺少正确过滤,提交部分PHP函数的请求,如phpinfo可使服务器返回大量系统配置信息。
|漏洞EXP
source: http://www.securityfocus.com/bid/6917/info

A vulnerability has been discovered in Nuked-Klan which may be exploited to execute certain PHP functions on a target server. This issue occurs in the 'Team', 'News', and 'Lien' modules and is due to insufficient sanitization of user-supplied URI parameters.

This issue may be exploited by a remote attacker to obtain sensitive server information, which could aid in launching further attacks against a target system.

The vulnerability was reported for Nuked-Klan beta 1.3; earlier versions may also be affected. 

http://www.example.org/index.php?file=Team&op=phpinfo
http://www.example.org/index.php?file=News&op=phpinfo
http://www.example.org/index.php?file=Liens&op=phpinfo
|参考资料

来源:XF
名称:nukedklan-information-disclosure(11424)
链接:http://xforce.iss.net/xforce/xfdb/11424
来源:BID
名称:6917
链接:http://www.securityfocus.com/bid/6917
来源:BUGTRAQ
名称:20030221[SCSA-006]XSS&FunctionExecutionVulnerabilitiesinNuked-Klan;
链接:http://archives.neohapsis.com/archives/bugtraq/2003-02/0276.html
来源:NSFOCUS
名称:4447
链接:http://www.nsfocus.net/vulndb/4447

相关推荐: Microsoft Outlook Javascript Execution Vulnerability

Microsoft Outlook Javascript Execution Vulnerability 漏洞ID 1102286 漏洞类型 Design Error 发布时间 2002-03-21 更新时间 2002-03-21 CVE编号 N/A CNNV…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享