Web-ERP配置文件远程访问漏洞

Web-ERP配置文件远程访问漏洞

漏洞ID 1203004 漏洞类型 权限许可和访问控制
发布时间 2003-03-01 更新时间 2003-12-31
图片[1]-Web-ERP配置文件远程访问漏洞-安全小百科CVE编号 CVE-2003-1383
图片[2]-Web-ERP配置文件远程访问漏洞-安全小百科CNNVD-ID CNNVD-200312-106
漏洞平台 N/A CVSS评分 7.5
|漏洞来源
https://cxsecurity.com/issue/WLB-2007100078
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-106
|漏洞详情
WEB-ERP是一款基于WEB的企业资源计划软件。WEB-ERP没有充分限制用户对配置文件的访问,远程攻击者可以利用这个漏洞获得系统敏感信息。WEB-ERP的配置文件logicworks.ini包含了应用程序使用的MySQL用户名和密码,这个文件系统没有任何访问限制,任意攻击者可以通过访问此文件获得这些敏感信息,利用这些信息可以对数据库进行恶意操作。
|漏洞EXP
==================================
Security REPORT web-erp 0.1.4 and earlier
==================================
Product: web-erp 0.1.4 and earlier
Vulnerabilities: full database access
Vendor: Phil Daintree (http://web-erp.sourceforge.net/)
Vendor-Status: E-Mail to "p.daintree (at) xtra.co (dot) nz [email concealed]" date: 27.02.2003
Vendor-Patch: Vendor reports problem fixed in new version 0.1.5 (27.02.2003)

Local: YES
Remote: YES

============
Introduction
============
From web site:
"WEB-ERP aims to provide a company with all the tools it needs to manage
multi-currency debtors, multi-location stocks, multi-currency creditors as
well as it's general accounting needs."

=====================
Vulnerability Details
=====================
1) FULL DATABASE ACCESS

http-requests to:

---*---
http://server/logicworks.ini
---*---

display the contents of this configuration file, unless the web server is
specifically configured to handle .ini files differently.  The contents
include the MySQL username and password used by the application.  With this
username/password, a malicious person could connect to MySQL direct and add,
modify, and delete data.

severity: HIGH

=======
Remarks
=======
The author was very responsive and released a new, corrected version the
same day.

This vulnerability report was made using a recent post by Martin Eiszner as
a template.  Any similarity is no coincidence.

====================
Recommended Hotfixes
====================
Upgrade to 0.1.5, which the author reports fixes this problem.

=======
Contact
=======

Ryan Fox
rfox (at) amerisuk (dot) com [email concealed]
|参考资料

来源:XF
名称:weberp-logicworks-ini-access(11443)
链接:http://xforce.iss.net/xforce/xfdb/11443
来源:BID
名称:6996
链接:http://www.securityfocus.com/bid/6996
来源:BUGTRAQ
名称:20030301web-erp0.1.4databaseaccessvulnerability
链接:http://www.securityfocus.com/archive/1/313575
来源:SREASON
名称:3257
链接:http://securityreason.com/securityalert/3257
来源:NSFOCUS
名称:4495
链接:http://www.nsfocus.net/vulndb/4495

相关推荐: Mike Spice My Classifieds Input Validation Vulnerability

Mike Spice My Classifieds Input Validation Vulnerability 漏洞ID 1102598 漏洞类型 Input Validation Error 发布时间 2002-01-09 更新时间 2002-01-09 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享