Working Resources BadBlue远程信息泄露漏洞

Working Resources BadBlue远程信息泄露漏洞

漏洞ID 1203593 漏洞类型 信息泄露
发布时间 2002-11-25 更新时间 2002-12-31
图片[1]-Working Resources BadBlue远程信息泄露漏洞-安全小百科CVE编号 CVE-2002-2289
图片[2]-Working Resources BadBlue远程信息泄露漏洞-安全小百科CNNVD-ID CNNVD-200212-266
漏洞平台 N/A CVSS评分 5.0
|漏洞来源
https://cxsecurity.com/issue/WLB-2007100064
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-266
|漏洞详情
BadBlue是一款由WoringResources开发的P2P文件共享应用程序,可使用在MicrosoftWindows操作系统下。BadBlue默认的soinfo.php脚本会显示过多的敏感信息,远程攻击者可以利用这个漏洞获得例如数据库密码等敏感信息,可对系统进一步进行攻击。如果BadBlue服务程序开启了PHP支持功能,攻击者请求BadBlue包含的soinfo.php脚本将会泄露很多系统敏感信息,因为soinfo.php脚本包含如下代码:–soinfo.php—-soinfo.php–攻击者可以获得包括ODBC数据密码等敏感信息,借此可以帮助攻击者对系统进一步攻击。
|漏洞EXP
BadBlue is a P2P/Web server offered for Microsoft Windows operating systems
by Working Resources.  It has a bad security record -- file disclosure,
remote administration, denials of service, buffer overflows, directory
traversals, and more cross-site scripting flaws than I care to count.  We
can add information disclosure to that list, and add a new XSS hole to the
count.

* soinfo.php - Massive Information Leak

If running with PHP enabled, the BadBlue server's default soinfo.php script
can be made to cough up substantial amounts of information, including ODBC
passwords:

-- soinfo.php --
<?php
    phpinfo();
?>
-- soinfo.php --

Yielding this data to an attacker, in combination with access to the
database allows for a compromise of the database.

* Cross-Site Scripting in ext.dll Search Page -- Again

I've discovered another flaw in BadBlue's search engine allowing for
cross-site scripting:

');alert(document.cookie);//
')" style="left:expression(eval('alert(document.cookie)'))">

Either of these two queries will execute the alert(document.cookie) command.
You get the idea. :-)
|参考资料

来源:XF
名称:badblue-soinfo-odbc-passwords(10690)
链接:http://xforce.iss.net/xforce/xfdb/10690
来源:BID
名称:6243
链接:http://www.securityfocus.com/bid/6243
来源:FULLDISC
名称:20021124BadBlueXSS/InformationDisclosureVulnerabilities
链接:http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2002-11/0329.html
来源:SREASON
名称:3243
链接:http://securityreason.com/securityalert/3243
来源:BUGTRAQ
名称:20021124BadBlueXSS/InformationDisclosureVulnerabilities
链接:http://online.securityfocus.com/archive/1/300992
来源:NSFOCUS
名称:3903
链接:http://www.nsfocus.net/vulndb/3903

相关推荐: Akfingerd Local Denial Of Service Attack

Akfingerd Local Denial Of Service Attack 漏洞ID 1101217 漏洞类型 Design Error 发布时间 2002-12-05 更新时间 2002-12-05 CVE编号 N/A CNNVD-ID N/A 漏洞平…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享