OpenBB隐私信息泄露漏洞

OpenBB隐私信息泄露漏洞

漏洞ID 1107910 漏洞类型 未知
发布时间 2004-04-26 更新时间 2005-10-20
图片[1]-OpenBB隐私信息泄露漏洞-安全小百科CVE编号 CVE-2004-1968
图片[2]-OpenBB隐私信息泄露漏洞-安全小百科CNNVD-ID CNNVD-200404-094
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/24061
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200404-094
|漏洞详情
OpenBulletinBoard(OpenBB)1.0.6及其早期版本文件myhome.php中的readmsg活动存在漏洞。远程攻击者可以通过转换id参数读取任意信息。
|漏洞EXP
source: http://www.securityfocus.com/bid/10217/info

It has been reported that OpenBB is affected by a private message disclosure vulnerability. This issue is due to a design error that fails to validate user credentials.

This issue might allow an attacker to read arbitrary private messages posted to the bulletin board; limiting confidentiality.

http:/www.example.com/forum/myhome.php?action=readmsg&id=[message_id]&box=inbox
|参考资料

来源:XF
名称:openbb-myhomephp-obtain-information(15970)
链接:http://xforce.iss.net/xforce/xfdb/15970
来源:BID
名称:10217
链接:http://www.securityfocus.com/bid/10217
来源:SECTRACK
名称:1009935
链接:http://securitytracker.com/id?1009935
来源:SECUNIA
名称:11481
链接:http://secunia.com/advisories/11481
来源:BUGTRAQ
名称:20040425MultipleVulnerabilitiesInOpenBB
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=108301983206107&w;=2

相关推荐: socket.c for rsync缓冲区溢出漏洞

socket.c for rsync缓冲区溢出漏洞 漏洞ID 1107716 漏洞类型 缓冲区溢出 发布时间 2004-02-13 更新时间 2004-02-13 CVE编号 CVE-2004-2093 CNNVD-ID CNNVD-200402-040 漏洞…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享