pMachine 1.0/2.x – ‘/lib/’ Multiple Script Direct Request Full Path Disclosures

pMachine 1.0/2.x – ‘/lib/’ Multiple Script Direct Request Full Path Disclosures

漏洞ID 1053979 漏洞类型
发布时间 2003-06-19 更新时间 2003-06-19
图片[1]-pMachine 1.0/2.x – ‘/lib/’ Multiple Script Direct Request Full Path Disclosures-安全小百科CVE编号 N/A
图片[2]-pMachine 1.0/2.x – ‘/lib/’ Multiple Script Direct Request Full Path Disclosures-安全小百科CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/22808
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/7980/info

It has been reported that pMachine is prone to remote a patch disclosure vulnerability when accessing various scripts.

When a request is made for a target PHP script, possibly requiring a blank URI parameter, pMachine is said to throw an exception. When this occurs, the resulting error page discloses the installation directory of the respective PHP script. 

http://www.example.com/Path_To_pMachine/lib/weblog.add.php
http://www.example.com/Path_To_pMachine/lib/comment.add.php

相关推荐: Oracle 8 Server ‘TNSLSNR80.EXE’ DoS Vulnerability

Oracle 8 Server ‘TNSLSNR80.EXE’ DoS Vulnerability 漏洞ID 1103283 漏洞类型 Failure to Handle Exceptional Conditions 发布时间 2001-04-18 更新时间 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享