PHP-Nuke SQL_Debug调试信息泄露漏洞

PHP-Nuke SQL_Debug调试信息泄露漏洞

漏洞ID 1106581 漏洞类型 设计错误
发布时间 2002-01-18 更新时间 2005-10-20
图片[1]-PHP-Nuke SQL_Debug调试信息泄露漏洞-安全小百科CVE编号 CVE-2002-2032
图片[2]-PHP-Nuke SQL_Debug调试信息泄露漏洞-安全小百科CNNVD-ID CNNVD-200212-243
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21233
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-243
|漏洞详情
PHP-Nuke是一个网站创建和管理工具,它可以用很多数据库软件作为后端,比如MySQL、PostgreSQL、mSQL、Interbase、Sybase等。PHP-Nuke在脚本中的调试信息处理存在问题,可以使远程攻击者得到数据库查询请求的一些敏感信息。sql_layer.php脚本有一个调试功能可以被攻击者利用来获得所有PHP-Nuke的查询请求信息。对调试功能的访问并不只限于管理员。远程攻击者可能利用这个漏洞得到数据库相关的敏感信息并进一步攻击数据库所在的Web服务器。
|漏洞EXP
source: http://www.securityfocus.com/bid/3906/info

PHPNuke is a website creation/maintenance tool. It is can be back-ended by a number of database products such as MySQL, PostgreSQL, mSQL, Interbase, Sybase, etc.

The sql_layer.php script contains a debugging feature that may be used by attackers to disclose sensitive information about all SQL queries made by PHPNuke. Access to the debugging feature is not restricted to administrators.

This may be used by a remote attacker to disclose sensitive information about the database which may contribute to further attacks against the website running PHPNuke and the database.

It is not known whether PostNuke is also affected by this issue. 

The following URLs may be used to access the debugging features:

http://www.vulnerable-site.com/index.php?sql_debug=1

or

http://www.vulnerable-site.com/modules.php?name=Members_List&&sql_debug=1
|参考资料

来源:BID
名称:3906
链接:http://www.securityfocus.com/bid/3906
来源:www.securityfaq.com
链接:http://www.securityfaq.com/unixfocus/5OP041P6BE.html
来源:NSFOCUS
名称:2145
链接:http://www.nsfocus.net/vulndb/2145

相关推荐: Xerox WorkCentre Multiple Page Fax Information Disclosure Vulnerability

Xerox WorkCentre Multiple Page Fax Information Disclosure Vulnerability 漏洞ID 1096985 漏洞类型 Design Error 发布时间 2005-03-11 更新时间 2005-0…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享