SIPS 0.2.2 – User Information Disclosure

SIPS 0.2.2 – User Information Disclosure

漏洞ID 1107247 漏洞类型
发布时间 2003-03-18 更新时间 2003-03-18
图片[1]-SIPS 0.2.2 – User Information Disclosure-安全小百科CVE编号 CVE-2003-1553
图片[2]-SIPS 0.2.2 – User Information Disclosure-安全小百科CNNVD-ID N/A
漏洞平台 Multiple CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/22381
https://cxsecurity.com/issue/WLB-2008030073
|漏洞详情
This vulnerability has been modified since it was last analyzed by the NVD. It is awaiting reanalysis which may result in further changes to the information provided.
|漏洞EXP
source: http://www.securityfocus.com/bid/7134/info

It has been reported that authentication is not required to view user account information. As a result, an unauthorized remote attacker may be able to view potentially sensitive information. This may aid in launching further attacks against a target user or system.

http://www.example.com/[sips_directory]/sipssys/users/[first_letter_of_UserID]/
|参考资料
resource:
hyperlink:http://securityreason.com/securityalert/3780
resource:Exploit
hyperlink:http://www.securityfocus.com/archive/1/archive/1/315504/30/25460/threaded
resource:Exploit
hyperlink:http://www.securityfocus.com/bid/7134
resource:
hyperlink:https://exchange.xforce.ibmcloud.com/vulnerabilities/11572

相关推荐: Sun Solaris AT Command Arbitrary File Deletion Vulnerability

Sun Solaris AT Command Arbitrary File Deletion Vulnerability 漏洞ID 1100924 漏洞类型 Input Validation Error 发布时间 2003-01-27 更新时间 2003-01…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享