Mambo Site Server phpinfo.php信息泄露漏洞

Mambo Site Server phpinfo.php信息泄露漏洞

漏洞ID 1107130 漏洞类型 配置错误
发布时间 2002-12-12 更新时间 2002-12-31
图片[1]-Mambo Site Server phpinfo.php信息泄露漏洞-安全小百科CVE编号 CVE-2002-2247
图片[2]-Mambo Site Server phpinfo.php信息泄露漏洞-安全小百科CNNVD-ID CNNVD-200212-325
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/22086
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-325
|漏洞详情
MamboSiteServer是一款免费开放源代码WEB内容管理工具,由PHP编写。Mambo包含的默认脚本对用户请求应答不正确,远程攻击者可以利用这个漏洞获得服务器信息,如路径和环境变量。Mambo管理目录包含的默认脚本phpinfo.php可远程被用户访问,攻击者可以直接访问此脚本,而获得大量如路径,PHP设置,环境变量等敏感信息。
|漏洞EXP
source: http://www.securityfocus.com/bid/6376/info

Mambo Site Server is a freely available, open source web content management tool. It is written in PHP, and available for Unix, Linux, and Microsoft Windows operating systems.

It has been reported that Mambo enables a script by default that may reveal sensitive information. The phpinfo.php script is packaged with Mambo, and installed by default in the administrator subdirectory. A remote user may use this script to gain information about the server, including path and environment information.

http://www.example.com/mambo/administrator/phpinfo.php
|参考资料

来源:BID
名称:6376
链接:http://www.securityfocus.com/bid/6376
来源:XF
名称:mambo-phpinfo-disclose-path(10853)
链接:http://xforce.iss.net/xforce/xfdb/10853
来源:BUGTRAQ
名称:20021212MultipleMamboSiteServersec-weaknesses
链接:http://archives.neohapsis.com/archives/bugtraq/2002-12/0111.html
来源:NSFOCUS
名称:4035
链接:http://www.nsfocus.net/vulndb/4035

相关推荐: PHP-Nuke 6.0 – Web Mail Remote PHP Script Execution

PHP-Nuke 6.0 – Web Mail Remote PHP Script Execution 漏洞ID 1053665 漏洞类型 发布时间 2002-12-16 更新时间 2002-12-16 CVE编号 N/A CNNVD-ID N/A 漏洞平台 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享